PT-2019-19897 · Abus · Abus Secvest

Matthias Deeg

+1

·

Published

2019-03-27

·

Updated

2020-08-24

·

CVE-2019-9862

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABUS Secvest wireless alarm system FUAA50000 version 3.01.01
Description An issue was discovered where sensitive data, such as the current rolling code state, is transmitted in cleartext due to the lack of "encrypted signal transmission". This allows an attacker to eavesdrop on the data.
Recommendations For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider implementing encrypted signal transmission to prevent eavesdropping of sensitive data. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9862

Affected Products

Abus Secvest