CVE-2019-9862
Summary
| CVE | CVE-2019-9862 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-27 14:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state). |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Abus | Secvest Wireless Alarm System Fuaa50000 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Alarm System Fuaa50000 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Alarm System Fuaa50000 Firmware | 3.01.01 | All | All | All |
| Operating System | Abus | Secvest Wireless Alarm System Fuaa50000 Firmware | 3.01.01 | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50014 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50014 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50014 Firmware | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50014 Firmware | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50015 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50015 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50015 Firmware | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50015 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-035.txt | MISC | www.syss.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.