CVE-2019-3997: Simplisafe SS3 Firmware
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.
Affected products
- Simplisafe SS3 Firmware: from 1.0, up to and including 1.3
Published 2020-01-16. Last modified 2026-06-17.