Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Authority · Co-dominant path
Account authority
The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.
Reusable artifact or reachable service
Anyone can download the Chirp Access app and extract its embedded static credential without touching a resident's device.
EvidenceNVD
Reusable multi-stage bridge
A public app artifact yields a credential that crosses into deployed access-control beacon configuration.
EvidenceNo direct citation — inspect the declared inference or assumption.
Bounded function authority
The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
The vendor must remove and rotate the embedded secret across the app and affected beacon population.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 3 - Reusable artifact or reachable service
Anyone can download the Chirp Access app and extract its embedded static credential without touching a resident's device.
- Execution complexity
EC 4 - Straightforward operation
The credential is stored in the app artifact, so extraction is a straightforward inspection task.
- Exposure
EX 3 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Beacon configuration can affect an access-control installation, but the confirmed evidence does not show remote door unlock or severe physical harm.
- Data / perception
DP 3 - Sensitive device or personal data
The exposed value is a shared production credential for beacon and backend configuration functions.
- Authority
AT 2 - Bounded function authority
The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
A public app artifact yields a credential that crosses into deployed access-control beacon configuration.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same embedded secret appears across app installations, so one extraction produces a portable credential.
- Execution scale
SX 3 - Deployment-wide with setup
Knowledge of the secret is deployment-wide, while applying it to a beacon still requires local radio proximity.
- Recovery burden
OR 4 - Fleet action or replacement
The vendor must remove and rotate the embedded secret across the app and affected beacon population.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATEDRead the scoring method →Safety · Co-dominant path
Device-control safety
The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.
Proximity or local access
Changing an installed beacon requires BLE proximity even after the shared application credential is known.
EvidenceNVD
One cross-boundary bridge
The embedded app credential crosses the BLE boundary into one deployed beacon.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
The install base needs updated app or firmware material that removes and rotates the shared credential.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Changing an installed beacon requires BLE proximity even after the shared application credential is known.
- Execution complexity
EC 3 - Reproducible exploit workflow
Once nearby, the attacker can use the recovered credential through the ordinary beacon-configuration workflow.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 2 - Operational safety effect
The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.
- Data / perception
DP 3 - Sensitive device or personal data
The path changes operational configuration of an access-control beacon rather than extracting resident data.
- Authority
AT 2 - Bounded function authority
Authority is limited to the exposed beacon settings and does not include lock commands, administrator control, or firmware signing.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The embedded app credential crosses the BLE boundary into one deployed beacon.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same shared credential can be presented to any affected beacon.
- Execution scale
SX 2 - Proximity-bound repetition
Each target beacon must be approached over BLE, so execution remains proximity-bound.
- Recovery burden
OR 4 - Fleet action or replacement
The install base needs updated app or firmware material that removes and rotates the shared credential.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →Triage implication
Verify the authority transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVE recordsCVE-2024-2197
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197) at HIGH — the worst of 2 risk paths (authority, safety). The dominant consequence is privileged account or control authority.
Vulnerability
Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197). Reported attack vector: Adjacent (Bluetooth range, ~30m) per the revised NVD assessment; initial CISA claim alleged network/remote unlock but was retracted.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
ACCOUNT_AUTHORITY → HIGH
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATED
Exposure EX=3 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.
Hardcoded BEACON_PASSWORD (CWE-259/798) is embedded in the public Chirp Access app; an attacker downloads the app and extracts the static credential (RE:3 own-artifact, not physical; EC:4 trivial). The secret is a shared credential authenticating to beacon/back-end functions (DP:3 credential/firmware-tier secret). Confirmed authority is bounded to beacon config functions, not admin/fleet control, so AT:2. SR:4: one secret shared across all installs, fully portable. SX:3: knowledge is deployment-wide but turning it into effect still needs proximity, so not true remote fleet-scale (not 4). CH:3 bridges app->credential->device-config boundary. OR:4: remediation requires app/firmware update to rotate the embedded secret across the install base and vendor was unresponsive. EV:2 report-backed.
DEVICE_CONTROL_SAFETY → HIGH
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED
Exposure EX=2 (reachability-bound) · bands PH=ELEVATED · DP=HIGH · AT=ELEVATED → base HIGH · uplift recall-class recovery → assessed HIGH.
- Confirmed consequence per revised NVD/CISA (CVSS AV:A, I:L): an attacker within Bluetooth range (~30m) uses the hardcoded credential to modify Bluetooth beacon configuration, e.g. disabling proximity-unlock notifications on a smart-lock/keyless-entry system. RE:2 BLE/proximity. EC:3 standard once positioned. AT:2 bounded config control of one beacon, not lock-command/admin authority (the disputed remote-unlock claim was retracted, so not AT:3+/PH:4). PH:2: degrades a physical access-control convenience feature / availability of proximity unlock, no confirmed severe harm.
- perception_feeds_action — false: beacon config change does not drive a safety-relevant actuation in the confirmed scope. DP:3 config/operational integrity of an access-control device. SR:4 same shared secret enables this on any install. SX:2 per-device proximity needed. CH:2 crosses app->BLE->device boundary. OR:4 fix requires fleet-wide app/firmware update; vendor unresponsive. EV:2 report-backed; disputed higher-impact unlock scenario excluded to avoid inflation.
Published baseline
- v4.0 2.3 LOW —
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— CISA/ICS-CERT via NVD - v3.1 4.3 MEDIUM —
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N— CISA/ICS-CERT via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0033 (“Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)”), paths.cfse.ai/CPATH-2026-0033 (published 2026-06-03).