CVE-2020-9060

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.
References
Link Resource
https://doi.org/10.1109/ACCESS.2021.3138768 Broken Link
https://github.com/CNK2100/VFuzz-public Third Party Advisory
https://ieeexplore.ieee.org/document/9663293 Broken Link
https://kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:o:silabs:500_series_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:aeotec:zw090-a:3.95:*:*:*:*:*:*:*
cpe:2.3:o:fibaro:fgwpb-111:4.3:*:*:*:*:*:*:*
cpe:2.3:o:zooz:zen20:5.03:*:*:*:*:*:*:*
cpe:2.3:o:zooz:zen25:5.03:*:*:*:*:*:*:*
cpe:2.3:o:zooz:zst10:6.04:*:*:*:*:*:*:*

History

18 Jan 2022, 17:25

Type Values Removed Values Added
First Time Silabs
Zooz zen25
Aeotec zw090-a
Zooz zst10
Zooz
Fibaro fgwpb-111
Aeotec
Zooz zen20
Silabs 500 Series Firmware
Fibaro
CVSS v2 : unknown
v3 : unknown
v2 : 6.1
v3 : 6.5
CPE cpe:2.3:o:zooz:zen25:5.03:*:*:*:*:*:*:*
cpe:2.3:o:zooz:zst10:6.04:*:*:*:*:*:*:*
cpe:2.3:o:aeotec:zw090-a:3.95:*:*:*:*:*:*:*
cpe:2.3:o:zooz:zen20:5.03:*:*:*:*:*:*:*
cpe:2.3:o:silabs:500_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fibaro:fgwpb-111:4.3:*:*:*:*:*:*:*
CWE CWE-400
References (MISC) https://github.com/CNK2100/VFuzz-public - (MISC) https://github.com/CNK2100/VFuzz-public - Third Party Advisory
References (CERT-VN) https://kb.cert.org/vuls/id/142629 - (CERT-VN) https://kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource
References (MISC) https://ieeexplore.ieee.org/document/9663293 - (MISC) https://ieeexplore.ieee.org/document/9663293 - Broken Link
References (MISC) https://doi.org/10.1109/ACCESS.2021.3138768 - (MISC) https://doi.org/10.1109/ACCESS.2021.3138768 - Broken Link
References (CERT-VN) https://www.kb.cert.org/vuls/id/142629 - (CERT-VN) https://www.kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource

10 Jan 2022, 14:14

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-10 14:10

Updated : 2023-12-10 14:09


NVD link : CVE-2020-9060

Mitre link : CVE-2020-9060

CVE.ORG link : CVE-2020-9060


JSON object : View

Products Affected

aeotec

  • zw090-a

silabs

  • 500_series_firmware

zooz

  • zen20
  • zst10
  • zen25

fibaro

  • fgwpb-111
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-346

Origin Validation Error