CVE-2020-14157

HIGH

ABUS Secvest FUBE50001 Firmware - Cleartext Transmission of Sensitive Information via Wireless Communication

Title source: llm
STIX 2.1

Description

The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm system.

References (4)

Core 4
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=kCqAVYyahLc
Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Jun/26

Scores

CVSS v3 8.1
EPSS 0.0079
EPSS Percentile 51.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-319
Status published
Products (1)
abus/secvest_wireless_control_fube50001_firmware
Published Jun 17, 2020
Tracked Since Feb 18, 2026