Lucene search

K
nvd[email protected]NVD:CVE-2019-9863
HistoryMar 27, 2019 - 2:29 p.m.

CVE-2019-9863

2019-03-2714:29:02
CWE-330
web.nvd.nist.gov
2

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

79.7%

Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an unauthorized way.

Affected configurations

Nvd
Node
abussecvest_wireless_alarm_system_fuaa50000_firmwareMatch3.01.01
AND
abussecvest_wireless_alarm_system_fuaa50000Match-
Node
abussecvest_wireless_remote_control_fube50014_firmwareMatch-
AND
abussecvest_wireless_remote_control_fube50014Match-
Node
abussecvest_wireless_remote_control_fube50015_firmwareMatch-
AND
abussecvest_wireless_remote_control_fube50015Match-
VendorProductVersionCPE
abussecvest_wireless_alarm_system_fuaa50000_firmware3.01.01cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.01:*:*:*:*:*:*:*
abussecvest_wireless_alarm_system_fuaa50000-cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50014_firmware-cpe:2.3:o:abus:secvest_wireless_remote_control_fube50014_firmware:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50014-cpe:2.3:h:abus:secvest_wireless_remote_control_fube50014:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50015_firmware-cpe:2.3:o:abus:secvest_wireless_remote_control_fube50015_firmware:-:*:*:*:*:*:*:*
abussecvest_wireless_remote_control_fube50015-cpe:2.3:h:abus:secvest_wireless_remote_control_fube50015:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

79.7%

Related for NVD:CVE-2019-9863