Vulnerability Description
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silabs | Uzb-7 | 7.00 |
| Silabs | 700 Series Firmware | All versions |
Related Weaknesses (CWE)
References
- https://doi.org/10.1109/ACCESS.2021.3138768Broken Link
- https://github.com/CNK2100/VFuzz-publicThird Party Advisory
- https://ieeexplore.ieee.org/document/9663293Broken Link
- https://kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://doi.org/10.1109/ACCESS.2021.3138768Broken Link
- https://github.com/CNK2100/VFuzz-publicThird Party Advisory
- https://ieeexplore.ieee.org/document/9663293Broken Link
- https://kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-10137?
CVE-2020-10137 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE...
How severe is CVE-2020-10137?
CVE-2020-10137 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10137?
Check the references section above for vendor advisories and patch information. Affected products include: Silabs Uzb-7, Silabs 700 Series Firmware.