TROYANOSYVIRUS
Voltar para CVEs

CVE-2020-9060

MEDIUM
6.5

Descricao

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

Detalhes CVE

Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vetor de ataqueADJACENT_NETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/10/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

aeotec:zw090-afibaro:fgwpb-111silabs:500_series_firmwarezooz:zen20zooz:zen25zooz:zst10

Fraquezas (CWE)

CWE-346CWE-400CWE-400

Referencias

https://doi.org/10.1109/ACCESS.2021.3138768(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/CNK2100/VFuzz-public(af854a3a-2127-422b-91ae-364da2661108)
https://ieeexplore.ieee.org/document/9663293(af854a3a-2127-422b-91ae-364da2661108)
https://kb.cert.org/vuls/id/142629(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/142629(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.