CVE-2019-15911

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
20/12/2019
Last modified:
09/01/2020

Description

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:hg100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:hg100:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:mw100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:mw100:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:ws-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ws-101:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:ts-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts-101:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:as-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:as-101:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:ms-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ms-101:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:dl-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:dl-101:-:*:*:*:*:*:*:*