Lucene search

K
nvd[email protected]NVD:CVE-2020-28973
HistoryApr 21, 2021 - 7:15 p.m.

CVE-2020-28973

2021-04-2119:15:35
CWE-287
web.nvd.nist.gov
2
abus
secvest wireless
vulnerability
https interface
sensitive information
usernames
passwords
reconfigure alarm system
disable alarm system

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

53.3%

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.

Affected configurations

Nvd
Node
abussecvest_wireless_alarm_system_fuaa50000_firmwareMatch3.01.17
AND
abussecvest_wireless_alarm_system_fuaa50000Match-
VendorProductVersionCPE
abussecvest_wireless_alarm_system_fuaa50000_firmware3.01.17cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.17:*:*:*:*:*:*:*
abussecvest_wireless_alarm_system_fuaa50000-cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

53.3%

Related for NVD:CVE-2020-28973