QID 590827

Date Published: 2022-06-23

QID 590827: Schneider Electric Harmony eXLhoist Vulnerability (SEVD-2020-224-06)

Affected Product
Harmony eXLhoist base stations v04.00.02.00 and prior: ZARB12W,ZARB12H,ZARB18H,ZARB18W,ZARB18HM,ZARB18WM

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.1 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-224-06 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590827

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-224-06 URL Logo www.se.com/in/en/download/document/SEVD-2020-224-06/