{"api_version":"1","generated_at":"2026-07-23T09:42:48+00:00","cve":"CVE-2019-9861","urls":{"html":"https://cve.report/CVE-2019-9861","api":"https://cve.report/api/cve/CVE-2019-9861.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-9861","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-9861"},"summary":{"title":"CVE-2019-9861","description":"Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-05-14 17:29:00","updated_at":"2019-05-17 12:58:00"},"problem_types":["CWE-310"],"metrics":[],"references":[{"url":"https://seclists.org/bugtraq/2019/May/1","name":"20190503 [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","refsource":"BUGTRAQ","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Bugtraq: [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-005.txt","name":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-005.txt","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/May/3","name":"20190504 [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","refsource":"FULLDISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/152714/ABUS-Secvest-3.01.01-Cryptographic-Issues.html","name":"http://packetstormsecurity.com/files/152714/ABUS-Secvest-3.01.01-Cryptographic-Issues.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"ABUS Secvest 3.01.01 Cryptographic Issues ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-9861","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9861","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"9861","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"abus","cpe5":"secvest_wireless_alarm_system_fuaa50000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9861","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"abus","cpe5":"secvest_wireless_alarm_system_fuaa50000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9861","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"abus","cpe5":"secvest_wireless_alarm_system_fuaa50000_firmware","cpe6":"3.01.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9861","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"abus","cpe5":"secvest_wireless_alarm_system_fuaa50000_firmware","cpe6":"3.01.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-9861","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-005.txt","refsource":"MISC","name":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-005.txt"},{"refsource":"BUGTRAQ","name":"20190503 [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","url":"https://seclists.org/bugtraq/2019/May/1"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/152714/ABUS-Secvest-3.01.01-Cryptographic-Issues.html","url":"http://packetstormsecurity.com/files/152714/ABUS-Secvest-3.01.01-Cryptographic-Issues.html"},{"refsource":"FULLDISC","name":"20190504 [SYSS-2019-005]: ABUS Secvest - Proximity Key - Cryptographic Issues (CWE-310)","url":"http://seclists.org/fulldisclosure/2019/May/3"}]}},"nvd":{"publishedDate":"2019-05-14 17:29:00","lastModifiedDate":"2019-05-17 12:58:00","problem_types":["CWE-310"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:P/A:N","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.8},"severity":"MEDIUM","exploitabilityScore":6.5,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.01:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"9861","Ordinal":"147755","Title":"CVE-2019-9861","CVE":"CVE-2019-9861","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"9861","Ordinal":"1","NoteData":"Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"9861","Ordinal":"2","NoteData":"2019-05-14","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"9861","Ordinal":"3","NoteData":"2019-05-14","Type":"Other","Title":"Modified"}]}}}