CVE-2020-9060
Summary
| CVE | CVE-2020-9060 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-10 14:10:00 UTC |
| Updated | 2022-09-20 17:16:00 UTC |
| Description | Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Aeotec | Zw090-a | 3.95 | All | All | All |
| Operating System | Fibaro | Fgwpb-111 | 4.3 | All | All | All |
| Operating System | Silabs | 500 Series Firmware | All | All | All | All |
| Operating System | Zooz | Zen20 | 5.03 | All | All | All |
| Operating System | Zooz | Zen25 | 5.03 | All | All | All |
| Operating System | Zooz | Zst10 | 6.04 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#142629 - Silicon Labs Z-Wave chipsets contain multiple vulnerabilities | CERT-VN | kb.cert.org | |
| GitHub - CNK2100/VFuzz-public | MISC | github.com | |
| Riding the IoT Wave with VFuzz: Discovering Security Flaws in Smart Home | IEEE Journals & Magazine | IEEE Xplore | MISC | ieeexplore.ieee.org | |
| Riding the IoT Wave with VFuzz: Discovering Security Flaws in Smart Home | IEEE Journals & Magazine | IEEE Xplore | MISC | doi.org | |
| VU#142629 - Silicon Labs Z-Wave chipsets contain multiple vulnerabilities | CERT-VN | www.kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Carlos Nkuba Kayembe, Kim Seulbae, Sven Dietrich, and Heejo Lee
There are currently no legacy QID mappings associated with this CVE.