Vulnerability Description
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silabs | Zm5202 Firmware | - |
| Silabs | Zm5202 | - |
| Silabs | Zm5101 Firmware | - |
| Silabs | Zm5101 | - |
| Silabs | Sd3503 Firmware | - |
| Silabs | Sd3503 | - |
| Silabs | Sd3502 Firmware | - |
| Silabs | Sd3502 | - |
| Silabs | Zm5304 Firmware | - |
| Silabs | Zm5304 | - |
References
- http://z-wave.comNot Applicable
- https://github.com/ITSecLab-HSEL/CVE-2022-24611Third Party Advisory
- http://z-wave.comNot Applicable
- https://github.com/ITSecLab-HSEL/CVE-2022-24611Third Party Advisory
FAQ
What is CVE-2022-24611?
CVE-2022-24611 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave...
How severe is CVE-2022-24611?
CVE-2022-24611 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24611?
Check the references section above for vendor advisories and patch information. Affected products include: Silabs Zm5202 Firmware, Silabs Zm5202, Silabs Zm5101 Firmware, Silabs Zm5101, Silabs Sd3503 Firmware.