SimpliSafe develops a line of residential and small-business security systems centered on wireless monitoring hardware and cloud-connected control units, with vulnerabilities clustering around authentication and data-transmission weaknesses in its base-station firmware and management interfaces. The durable signal reflects the remote-access and wireless-connectivity demands of connected security devices, where improper authentication mechanisms and cleartext handling of sensitive credentials and sensor data create persistent exposure vectors that defenders should address through firmware updates and network segmentation. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplisafe over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11402MEDIUM SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. | May 24, 2018 | 6.6 | 21 | NO | NO |
CVE-2019-3998MEDIUM Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connec | Feb 13, 2020 | 5.5 | 17 | NO | NO |
CVE-2019-3997MEDIUM Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. | Jan 16, 2020 | 4.6 | 17 | NO | NO |
CVE-2018-11401MEDIUM In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification. | May 24, 2018 | 4.6 | 17 | NO | NO |
CVE-2018-11400MEDIUM In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power. | May 24, 2018 | 4.6 | 17 | NO | NO |
CVE-2018-11399MEDIUM SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alar | May 24, 2018 | 4.3 | 16 | NO | NO |
CVE-2020-5727MEDIUM Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. | May 2, 2020 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplisafe.
Media articles that mention a CVE ID that affects a product developed by Simplisafe — matched by CVE ID, not by vendor name.