PT-2018-15185 · Sigma Design · Z-Wave

Wyp

·

Publicado

2018-12-09

·

Atualizado

2019-10-03

·

CVE-2018-19983

CVSS v2.0

6.1

Média

VetorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sigma Design Z-Wave S0 through S2 devices
Description An issue was discovered in Sigma Design Z-Wave devices, where an attacker can conduct a Denial of Service (DoS) attack against the Z-Wave S0 Security version product. The attack involves continuously sending divided "Nonce Get (0x98 0x81)" frames, causing the node to generate a new random nonce and transition to wait mode. When another "Nonce Get" frame is received, the previous nonce value is discarded, and a new one is generated, resulting in the inability to decrypt received normal frames.
Recommendations For Sigma Design Z-Wave S0 through S2 devices, consider implementing a mechanism to limit the frequency of "Nonce Get" frames to prevent the DoS attack. As a temporary workaround, restrict the use of the "Nonce Get" frame until a patch is available.

Exploit

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19983

Produtos afetados

Z-Wave