← Registry

CPATH-2026-0033 · GENERAL IOT

Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths HIGH Dominant consequence ACCOUNT_AUTHORITY authority · Evidence EV:2 (report-backed) · Liveness MITIGATED
CPATH IDCPATH-2026-0033
CVE(s)CVE-2024-2197
Device / classChirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197) (GENERAL IOT)
VendorChirp Systems
Dominant consequenceACCOUNT_AUTHORITY (authority)
Paths verdictHIGH (worst of 2 paths)
Published baseline
v4.0 2.3 LOW CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X · CISA/ICS-CERT via NVD
v3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N · CISA/ICS-CERT via NVD
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 #2 #7 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

authority

ACCOUNT_AUTHORITY

HIGH
Reachability RE:3
Complexity EC:4
Consequence ACCOUNT_AUTHORITY
Scale SR:4 / SX:3
Verdict HIGH
Reachability 3
Complexity 4
Exposure 3
Physical / safety 2
Data / perception 3
Authority 2
Chainability 3
Reuse scale 4
Execution scale 3
Recovery 4
Evidence EV:2 · report-backed
Liveness MITIGATED
Vector CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATED

Physical/safety

DEVICE_CONTROL_SAFETY

HIGH
Reachability RE:2
Complexity EC:3
Consequence DEVICE_CONTROL_SAFETY
Scale SR:4 / SX:2
Verdict HIGH
Reachability 2
Complexity 3
Exposure 2
Physical / safety 2
Data / perception 3
Authority 2
Chainability 2
Reuse scale 4
Execution scale 2
Recovery 4
Evidence EV:2 · report-backed
Liveness MITIGATED
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED

Assessment

CFSE Consequence Paths assesses Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197) at HIGH — the worst of 2 risk paths (authority, safety). The dominant consequence is privileged account or control authority.

Vulnerability

Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197). Reported attack vector: Adjacent (Bluetooth range, ~30m) per the revised NVD assessment; initial CISA claim alleged network/remote unlock but was retracted.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

ACCOUNT_AUTHORITYHIGH

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATED

Exposure EX=3 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.

Hardcoded BEACON_PASSWORD (CWE-259/798) is embedded in the public Chirp Access app; an attacker downloads the app and extracts the static credential (RE:3 own-artifact, not physical; EC:4 trivial). The secret is a shared credential authenticating to beacon/back-end functions (DP:3 credential/firmware-tier secret). Confirmed authority is bounded to beacon config functions, not admin/fleet control, so AT:2. SR:4: one secret shared across all installs, fully portable. SX:3: knowledge is deployment-wide but turning it into effect still needs proximity, so not true remote fleet-scale (not 4). CH:3 bridges app->credential->device-config boundary. OR:4: remediation requires app/firmware update to rotate the embedded secret across the install base and vendor was unresponsive. EV:2 report-backed.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED

Exposure EX=2 (reachability-bound) · bands PH=ELEVATED · DP=HIGH · AT=ELEVATED → base HIGH · uplift recall-class recovery → assessed HIGH.

Published baseline

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0033 (“Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)”), paths.cfse.ai/CPATH-2026-0033 (published 2026-06-03).