An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30.20181117, allows an attacker to trigger arbitrary system functionality by replaying previously recorded signals. This lets an adversary, among other things, disarm an armed system.
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Securitashome_alarm_system_firmware | Securitashome | hpgw-g_0.0.2.23f_bg_u-itr-f1-bd_bl.a30.20181117 (including) | hpgw-g_0.0.2.23f_bg_u-itr-f1-bd_bl.a30.20181117 (including) |