CVE-2019-15913
Summary
| CVE | CVE-2019-15913 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-20 17:15:00 UTC |
| Updated | 2020-01-03 14:42:00 UTC |
| Description | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages. |
Risk And Classification
Problem Types: CWE-639
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Mi | Dgnwg03lm | - | All | All | All |
| Hardware | Mi | Dgnwg03lm | - | All | All | All |
| Operating System | Mi | Dgnwg03lm Firmware | - | All | All | All |
| Operating System | Mi | Dgnwg03lm Firmware | - | All | All | All |
| Hardware | Mi | Mccgq01lm | - | All | All | All |
| Hardware | Mi | Mccgq01lm | - | All | All | All |
| Operating System | Mi | Mccgq01lm Firmware | - | All | All | All |
| Operating System | Mi | Mccgq01lm Firmware | - | All | All | All |
| Hardware | Mi | Rtcgq01lm | - | All | All | All |
| Hardware | Mi | Rtcgq01lm | - | All | All | All |
| Operating System | Mi | Rtcgq01lm Firmware | - | All | All | All |
| Operating System | Mi | Rtcgq01lm Firmware | - | All | All | All |
| Hardware | Mi | Wsdcgq01lm | - | All | All | All |
| Hardware | Mi | Wsdcgq01lm | - | All | All | All |
| Operating System | Mi | Wsdcgq01lm Firmware | - | All | All | All |
| Operating System | Mi | Wsdcgq01lm Firmware | - | All | All | All |
| Hardware | Mi | Zncz03lm | - | All | All | All |
| Hardware | Mi | Zncz03lm | - | All | All | All |
| Operating System | Mi | Zncz03lm Firmware | - | All | All | All |
| Operating System | Mi | Zncz03lm Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-POC/CVE-2019-15913.md at master · chengcheng227/CVE-POC · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.