Vulnerability Description
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abus | Secvest Wireless Alarm System Fuaa50000 Firmware | 3.01.17 |
| Abus | Secvest Wireless Alarm System Fuaa50000 | - |
Related Weaknesses (CWE)
References
- https://eye.security/en/blog/breaking-abus-secvest-internet-connected-alarm-systThird Party Advisory
- https://eye.security/en/blog/breaking-abus-secvest-internet-connected-alarm-systThird Party Advisory
FAQ
What is CVE-2020-28973?
CVE-2020-28973 is a vulnerability with a CVSS score of 7.5 (HIGH). The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive informa...
How severe is CVE-2020-28973?
CVE-2020-28973 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28973?
Check the references section above for vendor advisories and patch information. Affected products include: Abus Secvest Wireless Alarm System Fuaa50000 Firmware, Abus Secvest Wireless Alarm System Fuaa50000.