PT-2025-3692 · Zigbee · Zigbee

Published

2025-01-15

·

Updated

2025-01-15

·

CVE-2024-7322

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ZigBee (affected versions not specified)
Description A ZigBee coordinator, router, or end device may change its node ID when it receives an unsolicited encrypted rejoin response. This change in node ID causes a Denial of Service (DoS). To recover from this DoS, the network must be re-established.
Recommendations To resolve the issue, the network must be re-established after a Denial of Service (DoS) occurs. As a temporary workaround, consider disabling the reception of unsolicited encrypted rejoin responses until a fix is available. Restrict access to the network to minimize the risk of exploitation.

Fix

DoS

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2024-7322

Affected Products

Zigbee