CVE-2020-5727 describes an authentication bypass vulnerability in SimpliSafe SS3 firmware version 1.4. This flaw allows a local, unauthenticated attacker to pair a rogue keypad to an armed SimpliSafe SS3 system. With a CVSS score of 4.6 (Medium), the attack requires physical proximity (AV:P) but is low complexity (AC:L) and requires no user interaction (UI:N), potentially leading to high integrity impact (I:H) by compromising the system's armed state. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6CPE matchmatch criteria | cpe:2.3:o:simplisafe:ss3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020SimpliSafe SS3 PIN Add Using Rogue Keypad
May 1, 2020