CVE-2019-17098

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/09/2020
Last modified:
08/10/2020

Description

Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:august:august_home:*:*:*:*:*:android:*:* 10.11.0 (including)
cpe:2.3:o:august:connect_wi-fi_bridge_firmware:*:*:*:*:*:*:*:* 2.2.12 (including)
cpe:2.3:h:august:connect_wi-fi_bridge:-:*:*:*:*:*:*:*