Lucene search

K
cve[email protected]CVE-2019-9659
HistoryMar 11, 2019 - 3:29 p.m.

CVE-2019-9659

2019-03-1115:29:00
CWE-294
web.nvd.nist.gov
36
chuango
burglar alarm
433 mhz
vulnerability
replay attack
nvd
eminent em8617 ov2 wifi alarm system

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.7%

The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.

Affected configurations

NVD
Node
chuangowifi_alarm_system_firmwareMatch-
AND
chuangowifi_alarm_systemMatch-
Node
chuangowifi\/cellular_smart_home_system_h4_plus_firmwareMatch-
AND
chuangowifi\/cellular_smart_home_system_h4_plusMatch-
Node
chuangoawv_plus_wifi_alarm_system_firmwareMatch-
AND
chuangoawv_plus_wifi_alarm_systemMatch-
Node
chuangog5w_3g_firmwareMatch-
AND
chuangog5w_3gMatch-
Node
chuangog5_plus_gsm\/sms\/rfid_touch_alarm_system_firmwareMatch-
AND
chuangog5_plus_gsm\/sms\/rfid_touch_alarm_systemMatch-
Node
chuangog3_gsm\/sms_alarm_system_firmwareMatch-
AND
chuangog3_gsm\/sms_alarm_systemMatch-
Node
chuangog5w_3g_firmwareMatch-
AND
chuangog5w_3gMatch-
Node
chuangob11_dual-network_alarm_system_firmwareMatch-
AND
chuangob11_dual-network_alarm_systemMatch-
Node
chuangoa8_pstn_alarm_system_firmwareMatch-
AND
chuangoa8_pstn_alarm_systemMatch-
Node
chuangoa11_pstn\/lcd\/rfid_touch_alarm_system_firmwareMatch-
AND
chuangoa11_pstn\/lcd\/rfid_touch_alarm_systemMatch-
Node
chuangocg-105s_on-site_alarm_system_firmwareMatch-
AND
chuangocg-105s_on-site_alarm_systemMatch-
Node
eminentem8617_ov2_wifi_alarm_system_firmwareMatch-
AND
eminentem8617_ov2_wifi_alarm_systemMatch-

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.7%

Related for CVE-2019-9659