CVE-2019-9863
Summary
| CVE | CVE-2019-9863 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-27 14:29:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an unauthorized way. |
Risk And Classification
Problem Types: CWE-330
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Abus | Secvest Wireless Alarm System Fuaa50000 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Alarm System Fuaa50000 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Alarm System Fuaa50000 Firmware | 3.01.01 | All | All | All |
| Operating System | Abus | Secvest Wireless Alarm System Fuaa50000 Firmware | 3.01.01 | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50014 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50014 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50014 Firmware | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50014 Firmware | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50015 | - | All | All | All |
| Hardware | Abus | Secvest Wireless Remote Control Fube50015 | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50015 Firmware | - | All | All | All |
| Operating System | Abus | Secvest Wireless Remote Control Fube50015 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-034.txt | MISC | www.syss.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.