PT-2021-22828 · Unknown · Securitashome
Published
2021-12-15
·
Updated
2022-01-07
·
CVE-2021-40170
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SecuritasHome home alarm system version HPGW-G 0.0.2.23F BG U-ITR-F1-BD BL.A30.20181117
Description
The issue allows an attacker to trigger arbitrary system functionality by replaying previously recorded signals, enabling an adversary to disarm an armed system among other actions.
Recommendations
For version HPGW-G 0.0.2.23F BG U-ITR-F1-BD BL.A30.20181117, consider implementing signal authentication or encryption to prevent replay attacks, and restrict access to the system's RF signal reception to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securitashome