CVE-2019-5014 describes an improper access control vulnerability within the Bluetooth Low Energy (BLE) functionality of the Winco Fireworks FireFly FW-1007 V2.0 device and its firmware. An attacker can exploit this by connecting to the device, potentially leading to a high availability impact. With a CVSS score of 6.5 (Medium), this vulnerability requires adjacent network access and low attack complexity, but does not necessitate user interaction or privileges. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:o:wincofireworks:fw-1007_firmware:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.