Lucene search

K
cveMitreCVE-2020-14158
HistoryJul 30, 2020 - 2:15 p.m.

CVE-2020-14158

2020-07-3014:15:12
CWE-287
mitre
web.nvd.nist.gov
61
abus
secvest
fumo50110
hybrid module
rf packet
security mechanism
wapploxx
authentication-bypass
cve-2020-14158
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

51.0%

The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.

Affected configurations

Nvd
Node
abussecvest_hybrid_fumo50110Match-
AND
abussecvest_hybrid_fumo50110_firmwareMatch-
VendorProductVersionCPE
abussecvest_hybrid_fumo50110-cpe:2.3:h:abus:secvest_hybrid_fumo50110:-:*:*:*:*:*:*:*
abussecvest_hybrid_fumo50110_firmware-cpe:2.3:o:abus:secvest_hybrid_fumo50110_firmware:-:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

51.0%

Related for CVE-2020-14158