First published: Thu Nov 16 2017(Updated: )
Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a locked door before leaving.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Key | <=2017-11-16 | |
Amazon Key |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16867 has a high-severity rating due to its potential for unauthorized access to homes.
To mitigate CVE-2017-16867, ensure your Amazon Key firmware is updated to the latest version beyond 2017-11-16.
Users of the Amazon Key system with Cloud Cam firmware versions up to 2017-11-16 are affected by CVE-2017-16867.
CVE-2017-16867 allows delivery drivers or attackers to freeze the Cloud Cam, enabling unauthorized entry into homes.
Yes, CVE-2017-16867 exploits the mishandling of 802.11 deauthentication frames by the Cloud Cam system.