CVE Database
/

CVE-2020-10137

Back to search

CVE-2020-10137

Published: Jan 9, 2022

Modified: Sep 16, 2024

PUBLISHED

Description

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

VendorProductVersions

Silicon Labs

UZB-7

affected
7.00

Weaknesses (CWE)

References

https://kb.cert.org/vuls/id/142629
third-party-advisory
x_refsource_CERT-VN
VU#142629
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now