PT-2021-11616 · Abus · Abus Secvest
Published
2021-04-20
·
Updated
2021-04-27
·
CVE-2020-28973
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
ABUS Secvest wireless alarm system version 3.01.17
Description:
The issue allows unauthorized access to sensitive information, including usernames and passwords, due to improper authentication of requests to the built-in HTTPS interface. This sensitive information can be used to reconfigure or disable the alarm system.
Recommendations:
For version 3.01.17, consider restricting access to the HTTPS interface until a patch is available. As a temporary workaround, limit the exposure of the alarm system to the internet to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abus Secvest