« Volver al listado

CVE-2019-12944

Estado: ModificadaAlta (7.5)—

Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-12944",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-15T14:15:12.300",
  "references": [
    {
      "url": "https://www.kth.se/polopoly_fs/1.914054.1561620889%21/Examensarbete%20Final.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.931930.1571073241%21/Vulnerability_Report_Glue_State_Consistency.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.914054.1561620889%21/Examensarbete%20Final.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.931930.1571073241%21/Vulnerability_Report_Glue_State_Consistency.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable."
    },
    {
      "lang": "es",
      "value": "Los dispositivos Glue Smart Lock versión 2.7.8, no bloquean apropiadamente el acceso de invitados en ciertas situaciones donde la conexión de red no está disponible."
    }
  ],
  "lastModified": "2026-06-17T02:15:46.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gluehome:glue_smart_lock_firmware:2.7.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8EC45AE-6A27-445E-A89B-AAF1BFA95A87"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gluehome:glue_smart_lock:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3FF19317-3E34-4B61-8669-C0EE71D38445"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}