HIGH · 7.5

CVE-2020-28973

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive informa...

Vulnerability Description

The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AbusSecvest Wireless Alarm System Fuaa50000 Firmware3.01.17
AbusSecvest Wireless Alarm System Fuaa50000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-28973?

CVE-2020-28973 is a vulnerability with a CVSS score of 7.5 (HIGH). The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive informa...

How severe is CVE-2020-28973?

CVE-2020-28973 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28973?

Check the references section above for vendor advisories and patch information. Affected products include: Abus Secvest Wireless Alarm System Fuaa50000 Firmware, Abus Secvest Wireless Alarm System Fuaa50000.