PT-2019-19897 · Abus · Abus Secvest
Matthias Deeg
+1
·
Published
2019-03-27
·
Updated
2020-08-24
·
CVE-2019-9862
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABUS Secvest wireless alarm system FUAA50000 version 3.01.01
Description
An issue was discovered where sensitive data, such as the current rolling code state, is transmitted in cleartext due to the lack of "encrypted signal transmission". This allows an attacker to eavesdrop on the data.
Recommendations
For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider implementing encrypted signal transmission to prevent eavesdropping of sensitive data. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abus Secvest