TROYANOSYVIRUS
Back to CVEs

CVE-2020-9058

HIGH
8.1

Description

Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.

CVE Details

CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/10/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

dome:dm501jasco:zw4201linear:lb60z-1silabs:500_series_firmware

Weaknesses (CWE)

CWE-311CWE-311

References

https://doi.org/10.1109/ACCESS.2021.3138768(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/CNK2100/VFuzz-public(af854a3a-2127-422b-91ae-364da2661108)
https://ieeexplore.ieee.org/document/9663293(af854a3a-2127-422b-91ae-364da2661108)
https://kb.cert.org/vuls/id/142629(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/142629(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.