Vulnerability Description
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silabs | Zgm130S037Hgn Firmware | s2 |
| Silabs | Zgm130S037Hgn | - |
| Silabs | Zm5202 Firmware | s2 |
| Silabs | Zm5202 | - |
| Silabs | Zm5101 Firmware | s2 |
| Silabs | Zm5101 | - |
| Silabs | Zgm2305A27Hgn Firmware | s2 |
| Silabs | Zgm2305A27Hgn | - |
| Silabs | Zgm230Sb27Hgn Firmware | s2 |
| Silabs | Zgm230Sb27Hgn | - |
Related Weaknesses (CWE)
References
- https://orangecyberdefense.com/global/blog/sensepost/blackhat-conference-z-wave-Third Party Advisory
- https://sensepost.com/cms/resources/conferences/2013/bh_zwave/Security%20EvaluatTechnical DescriptionThird Party Advisory
- https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgradExploitThird Party Advisory
- https://orangecyberdefense.com/global/blog/sensepost/blackhat-conference-z-wave-Third Party Advisory
- https://sensepost.com/cms/resources/conferences/2013/bh_zwave/Security%20EvaluatTechnical DescriptionThird Party Advisory
- https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgradExploitThird Party Advisory
FAQ
What is CVE-2013-20003?
CVE-2013-20003 is a vulnerability with a CVSS score of 8.3 (HIGH). Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
How severe is CVE-2013-20003?
CVE-2013-20003 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-20003?
Check the references section above for vendor advisories and patch information. Affected products include: Silabs Zgm130S037Hgn Firmware, Silabs Zgm130S037Hgn, Silabs Zm5202 Firmware, Silabs Zm5202, Silabs Zm5101 Firmware.