PT-2023-27780 · Ember · Ember Znet

Published

2023-10-04

·

Updated

2024-09-26

·

CVE-2023-41094

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ember ZNet versions 7.1.3 through 7.1.5 Ember ZNet versions 7.2.0 through 7.2.3
Description The issue is related to TouchLink packets being processed after a timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime. This may allow a device to be added outside of the valid TouchLink range or pairing duration.
Recommendations For Ember ZNet versions 7.1.3 through 7.1.5, update to a version later than 7.1.5 to resolve the issue. For Ember ZNet versions 7.2.0 through 7.2.3, update to a version later than 7.2.3 to resolve the issue. As a temporary workaround, consider restricting the use of TouchLink packets to minimize the risk of exploitation.

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41094

Affected Products

Ember Znet