// For flags

CVE-2020-9061

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.

Los dispositivos Z-Wave que usan los conjuntos de chips de las series 500 y 700 de Silicon Labs, incluyendo pero sin limitarse a SiLabs UZB-7 versión 7.00, ZooZ ZST10 versión 6.04, Aeon Labs ZW090-A versión 3.95 y Samsung STH-ETH-200 versión 6.04, son susceptibles a una denegación de servicio por medio de mensajes de enrutamiento malformados

*Credits: Carlos Nkuba Kayembe, Kim Seulbae, Sven Dietrich, and Heejo Lee
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-02-18 CVE Reserved
  • 2022-01-07 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-285: Improper Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Aeotec
Search vendor "Aeotec"
Zw090-a
Search vendor "Aeotec" for product "Zw090-a"
3.95
Search vendor "Aeotec" for product "Zw090-a" and version "3.95"
-
Affected
Samsung
Search vendor "Samsung"
Sth-eth-200
Search vendor "Samsung" for product "Sth-eth-200"
6.04
Search vendor "Samsung" for product "Sth-eth-200" and version "6.04"
-
Affected
Silabs
Search vendor "Silabs"
Uzb-7
Search vendor "Silabs" for product "Uzb-7"
7.00
Search vendor "Silabs" for product "Uzb-7" and version "7.00"
-
Affected
Zooz
Search vendor "Zooz"
Zst10
Search vendor "Zooz" for product "Zst10"
6.04
Search vendor "Zooz" for product "Zst10" and version "6.04"
-
Affected
Silabs
Search vendor "Silabs"
500 Series Firmware
Search vendor "Silabs" for product "500 Series Firmware"
*-
Affected
Silabs
Search vendor "Silabs"
700 Series Firmware
Search vendor "Silabs" for product "700 Series Firmware"
--
Affected