perception
DATA_PRIVACY
Vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:3/EX:2/PH:0/DP:3/AT:2/CH:3/SR:4/SX:2/OR:3/EV:3/LS:HISTORICAL CPATH-2026-0034 · GENERAL IOT
DATA_PRIVACY perception · Evidence EV:3 (reproduced / report-backed) · Liveness HISTORICAL | CPATH ID | CPATH-2026-0034 |
| CVE(s) | CVE-2019-17098 |
| Device / class | August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098) (GENERAL IOT) |
| Vendor | August |
| Dominant consequence | DATA_PRIVACY (perception) |
| Paths verdict | HIGH (worst of 1 path) |
| Published baseline | v3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N · NVDv3.1 3.5 LOW CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N · Bitdefender via NVD |
| Baseline relationship | ▼ Paths higher |
| Consequence dimension(s) | #1 #7 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
perception
DATA_PRIVACYCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:3/EX:2/PH:0/DP:3/AT:2/CH:3/SR:4/SX:2/OR:3/EV:3/LS:HISTORICAL CFSE Consequence Paths assesses August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098) at HIGH — the worst of 1 risk path (perception). The dominant consequence is exposure of sensitive data.
August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098). Reported attack vector: Adjacent network (AV:A); attacker within Wi-Fi range during/around device provisioning.
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DATA_PRIVACY → HIGHCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:3/EX:2/PH:0/DP:3/AT:2/CH:3/SR:4/SX:2/OR:3/EV:3/LS:HISTORICAL
Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps privacy-only cap → assessed HIGH.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N — NVDCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N — Bitdefender via NVDThe published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0034 (“August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098)”), paths.cfse.ai/CPATH-2026-0034 (published 2026-06-03).