Описание
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
Ссылки
- Third Party Advisory
- Technical DescriptionThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Technical DescriptionThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:silabs:zgm130s037hgn_firmware:s2:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm130s037hgn:-:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:o:silabs:zm5202_firmware:s2:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zm5202:-:*:*:*:*:*:*:*
Конфигурация 3
Одновременно
cpe:2.3:o:silabs:zm5101_firmware:s2:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zm5101:-:*:*:*:*:*:*:*
Конфигурация 4
Одновременно
cpe:2.3:o:silabs:zgm2305a27hgn_firmware:s2:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm2305a27hgn:-:*:*:*:*:*:*:*
Конфигурация 5
Одновременно
cpe:2.3:o:silabs:zgm230sb27hgn_firmware:s2:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sb27hgn:-:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00141
Низкий
8.3 High
CVSS3
7.9 High
CVSS2
Дефекты
CWE-327
CWE-338
Связанные уязвимости
github
почти 4 года назад
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
EPSS
Процентиль: 34%
0.00141
Низкий
8.3 High
CVSS3
7.9 High
CVSS2
Дефекты
CWE-327
CWE-338