VulnerabilityModified
CVE-2018-11399
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
MEDIUM 4.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- simplisafe/u9k-es1000 firmware · simplisafe/u9k-kr1 firmware · simplisafe/u9k-ms1000 firmware · simplisafe/u9k-wt1000 firmware
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.