Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m2c-95xg-qw58

Опубликовано: 11 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

EPSS

Процентиль: 36%
0.00151
Низкий

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

EPSS

Процентиль: 36%
0.00151
Низкий

Дефекты

CWE-345