PT-2023-27780 · Ember · Ember Znet

Publicado

2023-10-04

·

Atualizado

2024-09-26

·

CVE-2023-41094

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ember ZNet versions 7.1.3 through 7.1.5 Ember ZNet versions 7.2.0 through 7.2.3
Description The issue is related to TouchLink packets being processed after a timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime. This may allow a device to be added outside of the valid TouchLink range or pairing duration.
Recommendations For Ember ZNet versions 7.1.3 through 7.1.5, update to a version later than 7.1.5 to resolve the issue. For Ember ZNet versions 7.2.0 through 7.2.3, update to a version later than 7.2.3 to resolve the issue. As a temporary workaround, consider restricting the use of TouchLink packets to minimize the risk of exploitation.

Correção

Missing Release of Resource after Effective Lifetime

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-41094

Produtos afetados

Ember Znet