First published: Tue Oct 27 2020(Updated: )
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message. It crashes in zclHandleExternal().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ti Z-stack | =3.0.1 | |
Ti Cc2538 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-27891.
The title of this vulnerability is 'The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not p…'.
The severity of CVE-2020-27891 is high with a CVSS score of 7.5.
The affected software is Texas Instruments CC2538 devices with Z-Stack 3.0.1.
To fix this vulnerability, update the Z-Stack software to a version that properly processes the ZCL Read Reporting Configuration Response message.