First published: Fri Dec 20 2019(Updated: )
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mi DGNWG03LM Firmware | ||
Mi DGNWG03LM Firmware | ||
Mi Zncz03lm Firmware | ||
Mi Zncz03lm Firmware | ||
Mi Mccgq01lm | ||
Mi Mccgq01lm Firmware | ||
Mi Wsdcgq01lm | ||
Mi Wsdcgq01lm Firmware | ||
Mi Rtcgq01lm | ||
Mi Rtcgq01lm Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15913 is considered a high-severity vulnerability due to its potential to compromise sensitive information and smart home devices.
To mitigate CVE-2019-15913, ensure that your ZigBee devices are updated to the latest firmware version that addresses this security issue.
CVE-2019-15913 affects Xiaomi smart home devices including DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, and RTCGQ01LM.
The risks associated with CVE-2019-15913 include unauthorized access to smart home devices, denial of service attacks, and the potential for message tampering.
CVE-2019-15913 is classified as an insecure key transport vulnerability in ZigBee communication.