CVE-2019-9483
 
Severity Score
9.1
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
Ring Doorbell de Amazon, en versiones anteriores a la 3.4.7, gestiona el cifrado de manera incorrecta, lo que permite a los atacantes obtener los datos de audio y vídeo o insertar un vídeo suplantado que no corresponde a la persona real que se encuentra en la puerta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-02-28 CVE Reserved
- 2019-03-01 CVE Published
- 2024-07-22 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://dojo.bullguard.com/dojo-by-bullguard/blog/ring | Third Party Advisory | |
https://www.theverge.com/2019/2/27/18243296/ring-doorbell-hacked-fake-images-security-experts | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amazon Search vendor "Amazon" | Ring Video Doorbell Firmware Search vendor "Amazon" for product "Ring Video Doorbell Firmware" | < 3.4.7 Search vendor "Amazon" for product "Ring Video Doorbell Firmware" and version " < 3.4.7" | - |
Affected
| in | Amazon Search vendor "Amazon" | Ring Video Doorbell Search vendor "Amazon" for product "Ring Video Doorbell" | - | - |
Safe
|