PT-2023-27780 · Ember · Ember Znet
Published
2023-10-04
·
Updated
2024-09-26
·
CVE-2023-41094
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ember ZNet versions 7.1.3 through 7.1.5
Ember ZNet versions 7.2.0 through 7.2.3
Description
The issue is related to TouchLink packets being processed after a timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime. This may allow a device to be added outside of the valid TouchLink range or pairing duration.
Recommendations
For Ember ZNet versions 7.1.3 through 7.1.5, update to a version later than 7.1.5 to resolve the issue.
For Ember ZNet versions 7.2.0 through 7.2.3, update to a version later than 7.2.3 to resolve the issue.
As a temporary workaround, consider restricting the use of TouchLink packets to minimize the risk of exploitation.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ember Znet