CVE-2020-10137

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
10/01/2022
Last modified:
18/01/2022

Description

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:silabs:uzb-7:7.00:*:*:*:*:*:*:*
cpe:2.3:o:silabs:700_series_firmware:*:*:*:*:*:*:*:*