Lucene search

K
cveMitreCVE-2020-28973
HistoryApr 21, 2021 - 7:15 p.m.

CVE-2020-28973

2021-04-2119:15:35
CWE-287
mitre
web.nvd.nist.gov
23
7
abus secvest
wireless alarm system
fuaa50000
v3.01.17
authentication vulnerability
nvd
cve-2020-28973

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

53.3%

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.

Affected configurations

Nvd
Node
abussecvest_wireless_alarm_system_fuaa50000_firmwareMatch3.01.17
AND
abussecvest_wireless_alarm_system_fuaa50000Match-
VendorProductVersionCPE
abussecvest_wireless_alarm_system_fuaa50000_firmware3.01.17cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.17:*:*:*:*:*:*:*
abussecvest_wireless_alarm_system_fuaa50000-cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

53.3%

Related for CVE-2020-28973