PT-2021-11616 · Abus · Abus Secvest

Published

2021-04-20

·

Updated

2021-04-27

·

CVE-2020-28973

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ABUS Secvest wireless alarm system version 3.01.17
Description: The issue allows unauthorized access to sensitive information, including usernames and passwords, due to improper authentication of requests to the built-in HTTPS interface. This sensitive information can be used to reconfigure or disable the alarm system.
Recommendations: For version 3.01.17, consider restricting access to the HTTPS interface until a patch is available. As a temporary workaround, limit the exposure of the alarm system to the internet to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28973

Affected Products

Abus Secvest