CVE-2019-15912: Input Validation
Published Dec 20, 2019
·Updated
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
Affected Software
14 affected components
ASUS HG100 firmware
ASUS HG100
ASUS Mw100 Firmware
ASUS MW100
ASUS Ws-101 Firmware
ASUS WS-101
ASUS Ts-101 Firmware
ASUS TS-101
ASUS As-101 Firmware
ASUS AS-101
ASUS Ms-101 Firmware
ASUS MS-101
ASUS Dl-101 Firmware
ASUS DL-101
Event History
Dec 20, 2019
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15912?
CVE-2019-15912 has a high severity due to its potential to enable multiple denial of service attacks.
2
How can I remediate CVE-2019-15912?
To remediate CVE-2019-15912, ensure that your affected ASUS devices are updated to the latest firmware version provided by ASUS.
3
What type of attacks can exploit CVE-2019-15912?
CVE-2019-15912 can be exploited to perform denial of service attacks via the ZigBee trust center rejoin procedure.
4
Is it safe to continue using devices affected by CVE-2019-15912?
Continuing to use devices affected by CVE-2019-15912 without applying mitigations poses a risk of service disruption.