PT-2023-27780 · Ember · Ember Znet
Publicado
2023-10-04
·
Atualizado
2024-09-26
·
CVE-2023-41094
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ember ZNet versions 7.1.3 through 7.1.5
Ember ZNet versions 7.2.0 through 7.2.3
Description
The issue is related to TouchLink packets being processed after a timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime. This may allow a device to be added outside of the valid TouchLink range or pairing duration.
Recommendations
For Ember ZNet versions 7.1.3 through 7.1.5, update to a version later than 7.1.5 to resolve the issue.
For Ember ZNet versions 7.2.0 through 7.2.3, update to a version later than 7.2.3 to resolve the issue.
As a temporary workaround, consider restricting the use of TouchLink packets to minimize the risk of exploitation.
Correção
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ember Znet