PT-2019-19898 · Abus · Abus Secvest Remote Controls+1
Published
2019-03-27
·
Updated
2021-07-21
·
CVE-2019-9863
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ABUS Secvest wireless alarm system FUAA50000 version 3.01.01
ABUS Secvest remote controls FUBE50014 (affected versions not specified)
ABUS Secvest remote controls FUBE50015 (affected versions not specified)
Description
The issue arises from the use of an insecure algorithm for rolling codes, allowing an attacker to predict valid future rolling codes. This enables unauthorized remote control of the alarm system.
Recommendations
For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider disabling remote control functionality until a secure algorithm for rolling codes is implemented.
For ABUS Secvest remote controls FUBE50014 and FUBE50015, restrict their use with the alarm system until a fix is provided, to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abus Secvest Remote Controls
Abus Secvest Wireless Alarm System