// For flags

CVE-2020-9060

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

Los dispositivos Z-Wave basados en los conjuntos de chips de la serie 500 de Silicon Labs que usan S2, incluidos, entre otros, ZooZ ZST10 versión 6.04, ZooZ ZEN20 versión 5.03, ZooZ ZEN25 versión 5.03, Aeon Labs ZW090-A versión 3. 95, y Fibaro FGWPB-111 versión 4.3, son susceptibles a una denegación de servicio y al agotamiento de recursos por medio de mensajes malformados SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, o NIF REQUEST

*Credits: Carlos Nkuba Kayembe, Kim Seulbae, Sven Dietrich, and Heejo Lee
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-02-18 CVE Reserved
  • 2022-01-07 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-346: Origin Validation Error
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Silabs
Search vendor "Silabs"
500 Series Firmware
Search vendor "Silabs" for product "500 Series Firmware"
*-
Affected
Aeotec
Search vendor "Aeotec"
Zw090-a
Search vendor "Aeotec" for product "Zw090-a"
3.95
Search vendor "Aeotec" for product "Zw090-a" and version "3.95"
-
Affected
Fibaro
Search vendor "Fibaro"
Fgwpb-111
Search vendor "Fibaro" for product "Fgwpb-111"
4.3
Search vendor "Fibaro" for product "Fgwpb-111" and version "4.3"
-
Affected
Zooz
Search vendor "Zooz"
Zen20
Search vendor "Zooz" for product "Zen20"
5.03
Search vendor "Zooz" for product "Zen20" and version "5.03"
-
Affected
Zooz
Search vendor "Zooz"
Zen25
Search vendor "Zooz" for product "Zen25"
5.03
Search vendor "Zooz" for product "Zen25" and version "5.03"
-
Affected
Zooz
Search vendor "Zooz"
Zst10
Search vendor "Zooz" for product "Zst10"
6.04
Search vendor "Zooz" for product "Zst10" and version "6.04"
-
Affected