Vulnerability Description
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| August | August Home | <= 10.11.0 |
| August | Connect Wi-Fi Bridge Firmware | <= 2.2.12 |
| August | Connect Wi-Fi Bridge | - |
Related Weaknesses (CWE)
References
- https://labs.bitdefender.com/2020/08/smart-locks-not-so-smart-with-wi-fi-securitThird Party Advisory
- https://labs.bitdefender.com/2020/08/smart-locks-not-so-smart-with-wi-fi-securitThird Party Advisory
FAQ
What is CVE-2019-17098?
CVE-2019-17098 is a vulnerability with a CVSS score of 3.5 (LOW). Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication ...
How severe is CVE-2019-17098?
CVE-2019-17098 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17098?
Check the references section above for vendor advisories and patch information. Affected products include: August August Home, August Connect Wi-Fi Bridge Firmware, August Connect Wi-Fi Bridge.