CVE-2017-16867: Medium severity Amazon Amazon Key Firmware vulnerability
Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a locked door before leaving.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16867?
CVE-2017-16867 has a high-severity rating due to its potential for unauthorized access to homes.
How do I fix CVE-2017-16867?
To mitigate CVE-2017-16867, ensure your Amazon Key firmware is updated to the latest version beyond 2017-11-16.
Who is affected by CVE-2017-16867?
Users of the Amazon Key system with Cloud Cam firmware versions up to 2017-11-16 are affected by CVE-2017-16867.
What are the risks associated with CVE-2017-16867?
CVE-2017-16867 allows delivery drivers or attackers to freeze the Cloud Cam, enabling unauthorized entry into homes.
Is there a known exploit for CVE-2017-16867?
Yes, CVE-2017-16867 exploits the mishandling of 802.11 deauthentication frames by the Cloud Cam system.