CVE-2020-9059 Information

Description

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example the Schlage BE468 version 3.42 door lock is vulnerable and fails open at a low battery level.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://github.com/CNK2100/VFuzz-public https://kb.cert.org/vuls/id/142629 https://ieeexplore.ieee.org/document/9663293 https://doi.org/10.1109/ACCESS.2021.3138768 https://www.kb.cert.org/vuls/id/142629

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

6.5

Share on: