« Back to list

CVE-2019-12944

Status: ModifiedHigh (7.5)—

Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-12944",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-15T14:15:12.300",
  "references": [
    {
      "url": "https://www.kth.se/polopoly_fs/1.914054.1561620889%21/Examensarbete%20Final.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.931930.1571073241%21/Vulnerability_Report_Glue_State_Consistency.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.914054.1561620889%21/Examensarbete%20Final.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kth.se/polopoly_fs/1.931930.1571073241%21/Vulnerability_Report_Glue_State_Consistency.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable."
    },
    {
      "lang": "es",
      "value": "Los dispositivos Glue Smart Lock versión 2.7.8, no bloquean apropiadamente el acceso de invitados en ciertas situaciones donde la conexión de red no está disponible."
    }
  ],
  "lastModified": "2026-06-17T02:15:46.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gluehome:glue_smart_lock_firmware:2.7.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8EC45AE-6A27-445E-A89B-AAF1BFA95A87"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gluehome:glue_smart_lock:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3FF19317-3E34-4B61-8669-C0EE71D38445"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}