CVE-2020-10137: Medium severity Silabs UZB-7 vulnerability
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FINDNODEINRANGE frames, allowing a remote, unauthenticated attacker to inject a FINDNODEINRANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10137?
CVE-2020-10137 is a vulnerability found in Z-Wave devices based on Silicon Labs 700 series chipsets using S2.
How does CVE-2020-10137 work?
CVE-2020-10137 allows a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming frames.
What is the severity of CVE-2020-10137?
CVE-2020-10137 has a severity rating of 6.5, classified as medium.
Are there any known affected software?
Yes, Z-Wave devices based on Silicon Labs 700 series chipsets using S2 and Silabs UZB-7 with firmware version 7.00 are known to be affected.
How can this vulnerability be fixed?
To fix CVE-2020-10137, it is recommended to apply the latest firmware updates provided by Silicon Labs for the affected devices.