CVE-2020-14158
Summary
| CVE | CVE-2020-14158 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-30 14:15:00 UTC |
| Updated | 2020-08-05 14:37:00 UTC |
| Description | The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Abus | Secvest Hybrid Fumo50110 | - | All | All | All |
| Hardware | Abus | Secvest Hybrid Fumo50110 | - | All | All | All |
| Operating System | Abus | Secvest Hybrid Fumo50110 Firmware | - | All | All | All |
| Operating System | Abus | Secvest Hybrid Fumo50110 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ABUS Secvest Hybrid Module FUMO50110 Authentication Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| Full Disclosure: [SYSS-2020-015]: ABUS Secvest Hybrid module (FUMO50110) - Authentication Bypass Using an Alternate Path or Channel (CWE-288) (CVE-2020-14158) | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-015.txt | MISC | www.syss.de | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.