Lucene search

K
cveMitreCVE-2019-9860
HistoryMar 27, 2019 - 3:29 p.m.

CVE-2019-9860

2019-03-2715:29:01
CWE-330
CWE-319
mitre
web.nvd.nist.gov
28
abus
secvest
wireless
remote control
vulnerability
unencrypted signal
rolling codes
attacker
desynchronize
fuaa50000
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

42.5%

Due to unencrypted signal communication and predictability of rolling codes, an attacker can “desynchronize” an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore.

Affected configurations

Nvd
Node
abussecvest_wireless_alarm_system_fuaa50000_firmwareMatch3.01.01
AND
abussecvest_wireless_alarm_system_fuaa50000Match-
Node
abussecvest_wireless_remote_control_fube50014_firmwareMatch-
AND
abussecvest_wireless_remote_control_fube50014Match-
Node
abussecvest_wireless_remote_control_fube50015_firmwareMatch-
AND
abussecvest_wireless_remote_control_fube50015Match-
VendorProductVersionCPE
abussecvest_wireless_alarm_system_fuaa50000_firmware3.01.01cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.01:*:*:*:*:*:*:*
abussecvest_wireless_alarm_system_fuaa50000-cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50014_firmware-cpe:2.3:o:abus:secvest_wireless_remote_control_fube50014_firmware:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50014-cpe:2.3:h:abus:secvest_wireless_remote_control_fube50014:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50015_firmware-cpe:2.3:o:abus:secvest_wireless_remote_control_fube50015_firmware:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50015-cpe:2.3:h:abus:secvest_wireless_remote_control_fube50015:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

42.5%

Related for CVE-2019-9860