CVE Feed

    Dashboard / CVE / CVE-2020-10137

    CVE-2020-10137

    Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

    Published:Jan 9, 2022
    Last Modified:Nov 21, 2024
    EPS:Jan 9, 2022
    EPSS Score:0.00151
    CVSS Score:6.5

    Affected Products

    Vendor
    Silabs
    Product
    700 Series Firmware
    Vendor
    Silabs
    Product
    Uzb-7

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High