ZeroHour

CVE-2020-9060

CVSS 3.1
6.5 medium
EPSS
<1%p43
Published
()
Modified
Description

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

Vendors
silabsaeotecfibarozooz
Products
500 series firmware, zw090-a, fgwpb-111, zen20, zen25, zst10
Weakness
CWE-346, CWE-400
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.