CVE Vulnerabilities

CVE-2019-9860

Cleartext Transmission of Sensitive Information

Published: Mar 27, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Due to unencrypted signal communication and predictability of rolling codes, an attacker can desynchronize an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Secvest_wireless_alarm_system_fuaa50000_firmware Abus 3.01.01 (including) 3.01.01 (including)

Potential Mitigations

References