Vulnerability Description
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silabs | 500 Series Firmware | All versions |
| Dome | Dm501 | 4.26 |
| Jasco | Zw4201 | 4.05 |
| Linear | Lb60Z-1 | 3.5 |
Related Weaknesses (CWE)
References
- https://doi.org/10.1109/ACCESS.2021.3138768Broken Link
- https://github.com/CNK2100/VFuzz-publicThird Party Advisory
- https://ieeexplore.ieee.org/document/9663293Broken Link
- https://kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://doi.org/10.1109/ACCESS.2021.3138768Broken Link
- https://github.com/CNK2100/VFuzz-publicThird Party Advisory
- https://ieeexplore.ieee.org/document/9663293Broken Link
- https://kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/142629Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-9058?
CVE-2020-9058 is a vulnerability with a CVSS score of 8.1 (HIGH). Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 versi...
How severe is CVE-2020-9058?
CVE-2020-9058 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9058?
Check the references section above for vendor advisories and patch information. Affected products include: Silabs 500 Series Firmware, Dome Dm501, Jasco Zw4201, Linear Lb60Z-1.