7.5
CVE-2020-28973
- EPSS 0.35%
- Veröffentlicht 21.04.2021 19:15:35
- Zuletzt bearbeitet 21.11.2024 05:23:25
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can then be used to reconfigure or disable the alarm system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abus ≫ Secvest Wireless Alarm System Fuaa50000 Firmware Version3.01.17
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.567 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.