PT-2022-9073 · Aeon+2 · Aeon Labs Zw090-A+4
Carlos Kayembe Nkuba
+3
·
Published
2022-01-07
·
Updated
2022-09-20
·
CVE-2020-9060
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ZooZ ZST10 version 6.04
ZooZ ZEN20 version 5.03
ZooZ ZEN25 version 5.03
Aeon Labs ZW090-A version 3.95
Fibaro FGWPB-111 version 4.3
Description
Z-Wave devices based on Silicon Labs 500 series chipsets using S2 are susceptible to denial of service and resource exhaustion via malformed
SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.Recommendations
For ZooZ ZST10 version 6.04, consider disabling the
SECURITY NONCE GET and SECURITY NONCE GET 2 functions until a patch is available.
For ZooZ ZEN20 version 5.03, restrict access to the NO OPERATION message to minimize the risk of exploitation.
For ZooZ ZEN25 version 5.03, avoid using the NIF REQUEST message in the affected API endpoint until the issue is resolved.
For Aeon Labs ZW090-A version 3.95, restrict access to the vulnerable module to minimize the risk of exploitation.
For Fibaro FGWPB-111 version 4.3, consider disabling the vulnerable function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Resource Exhaustion
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aeon Labs Zw090-A
Fibaro Fgwpb-111
Zooz Zen20
Zooz Zen25
Zooz Zst10