CVE-2023-50127

MEDIUM

Hozard alarm_system v1.0 - Unauthenticated Improper Authentication via SMS Commands

Title source: llm
STIX 2.1

Description

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0044
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
hozard/alarm_system 1.0
Published Jan 11, 2024
Tracked Since Feb 18, 2026