Simplisafe
simplisafe
7 CVEs • 16 products
Products (16)
Click to collapseToggle
Products (16)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. |
1Simplisafe 1Simplisafe Ss3 Firmware Jun 17, 2026 Feb 13, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to. |
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. |
1Simplisafe 1U9k Kp1000 Firmware Nov 21, 2024 May 24, 2018 N/A· v4 6.6 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. |
1Simplisafe 1U9k Bs1000 Firmware Nov 21, 2024 May 24, 2018 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification. |
1Simplisafe 1U9k Bs1000 Firmware Nov 21, 2024 May 24, 2018 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power. |
1Simplisafe 4U9k Es1000 Firmware U9k Kr1 FirmwareU9k Ms1000 Firmware+1 moreNov 21, 2024 May 24, 2018 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur. |