CVE-2019-9483
Summary
| CVE | CVE-2019-9483 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-01 05:29:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Amazon | Ring Video Doorbell | - | All | All | All |
| Hardware | Amazon | Ring Video Doorbell | - | All | All | All |
| Operating System | Amazon | Ring Video Doorbell Firmware | All | All | All | All |
| Operating System | Amazon | Ring Video Doorbell Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BullGuard 2021 | Antivirus and VPN for your home and business | MISC | dojo.bullguard.com | Third Party Advisory |
| The Ring Doorbell could have been hacked to show fake images, security experts find - The Verge | MISC | www.theverge.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.