// For flags

CVE-2018-25029

 

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.

La especificación Z-Wave requiere que la seguridad S2 pueda ser degradada a S0 u otros protocolos menos seguros, permitiendo a un atacante dentro del rango de radio durante el emparejamiento degradar y luego explotar una vulnerabilidad diferente (CVE-2013-20003) para interceptar y falsificar el tráfico

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-26 CVE Reserved
  • 2022-02-04 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • 2024-10-20 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Silabs
Search vendor "Silabs"
Zgm130s037hgn Firmware
Search vendor "Silabs" for product "Zgm130s037hgn Firmware"
s2
Search vendor "Silabs" for product "Zgm130s037hgn Firmware" and version "s2"
-
Affected
in Silabs
Search vendor "Silabs"
Zgm130s037hgn
Search vendor "Silabs" for product "Zgm130s037hgn"
--
Safe
Silabs
Search vendor "Silabs"
Zm5202 Firmware
Search vendor "Silabs" for product "Zm5202 Firmware"
s2
Search vendor "Silabs" for product "Zm5202 Firmware" and version "s2"
-
Affected
in Silabs
Search vendor "Silabs"
Zm5202
Search vendor "Silabs" for product "Zm5202"
--
Safe
Silabs
Search vendor "Silabs"
Zm5101 Firmware
Search vendor "Silabs" for product "Zm5101 Firmware"
s2
Search vendor "Silabs" for product "Zm5101 Firmware" and version "s2"
-
Affected
in Silabs
Search vendor "Silabs"
Zm5101
Search vendor "Silabs" for product "Zm5101"
--
Safe
Silabs
Search vendor "Silabs"
Zgm2305a27hgn Firmware
Search vendor "Silabs" for product "Zgm2305a27hgn Firmware"
s2
Search vendor "Silabs" for product "Zgm2305a27hgn Firmware" and version "s2"
-
Affected
in Silabs
Search vendor "Silabs"
Zgm2305a27hgn
Search vendor "Silabs" for product "Zgm2305a27hgn"
--
Safe
Silabs
Search vendor "Silabs"
Zgm230sb27hgn Firmware
Search vendor "Silabs" for product "Zgm230sb27hgn Firmware"
s2
Search vendor "Silabs" for product "Zgm230sb27hgn Firmware" and version "s2"
-
Affected
in Silabs
Search vendor "Silabs"
Zgm230sb27hgn
Search vendor "Silabs" for product "Zgm230sb27hgn"
--
Safe