CVE-2020-27890: High severity ti z-stack vulnerability
Published Oct 27, 2020
·Updated
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclParseInWriteCmd() and does not update the specific attribute's value.
Affected Software
2 affected components
ti Z-Stack=3.0.1
ti CC2538
Event History
Oct 27, 2020
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Zigbee protocol implementation issue?
The vulnerability ID for this Zigbee protocol implementation issue is CVE-2020-27890.
2
What is affected by this vulnerability?
This vulnerability affects Texas Instruments CC2538 devices with Z-Stack 3.0.1.
3
What is the severity rating of CVE-2020-27890?
The severity rating of CVE-2020-27890 is high with a score of 8.2.
4
How does this vulnerability manifest in the Zigbee protocol implementation?
This vulnerability causes a crash in zclParseInWriteCmd() when processing a ZCL Write Attributes No Response message, failing to update the specific attribute's value.
5
Is there a fix or patch available for this vulnerability?
There is no information provided regarding a fix or patch for this vulnerability.