Vulnerability Description
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simplisafe | U9K-Es1000 Firmware | - |
| Simplisafe | U9K-Es1000 | - |
| Simplisafe | U9K-Kr1 Firmware | - |
| Simplisafe | U9K-Kr1 | - |
| Simplisafe | U9K-Ms1000 Firmware | - |
| Simplisafe | U9K-Ms1000 | - |
| Simplisafe | U9K-Wt1000 Firmware | - |
| Simplisafe | U9K-Wt1000 | - |
Related Weaknesses (CWE)
References
- https://simplisafe.com/files/pdf/SimpliSafe_advisory_8-17-18.pdf
- https://www.simpleorsecure.net/simplisafe-security-advisory/Third Party Advisory
- https://simplisafe.com/files/pdf/SimpliSafe_advisory_8-17-18.pdf
- https://www.simpleorsecure.net/simplisafe-security-advisory/Third Party Advisory
FAQ
What is CVE-2018-11399?
CVE-2018-11399 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occu...
How severe is CVE-2018-11399?
CVE-2018-11399 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11399?
Check the references section above for vendor advisories and patch information. Affected products include: Simplisafe U9K-Es1000 Firmware, Simplisafe U9K-Es1000, Simplisafe U9K-Kr1 Firmware, Simplisafe U9K-Kr1, Simplisafe U9K-Ms1000 Firmware.