CVE-2020-10137
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
10/01/2022
Last modified:
18/01/2022
Description
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:silabs:uzb-7:7.00:*:*:*:*:*:*:* | ||
| cpe:2.3:o:silabs:700_series_firmware:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



