SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11399

SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.

MEDIUM 4.3EPSS 0.23%

Does this matter?

Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.

Description

SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
0.23% probability · 14th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
simplisafe/u9k-es1000 firmware · simplisafe/u9k-kr1 firmware · simplisafe/u9k-ms1000 firmware · simplisafe/u9k-wt1000 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.