CVE-2019-5014
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/05/2019
Last modified:
13/06/2022
Description
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wincofireworks:fw-1007_firmware:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:wincofireworks:fw-1007:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



