CVE-2020-27891: High severity ti z-stack vulnerability
Published Oct 27, 2020
·Updated
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message. It crashes in zclHandleExternal().
Affected Software
2 affected components
ti Z-Stack=3.0.1
ti CC2538
Event History
Oct 27, 2020
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-27891.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not p…'.
3
What is the severity of CVE-2020-27891?
The severity of CVE-2020-27891 is high with a CVSS score of 7.5.
4
Which software is affected by this vulnerability?
The affected software is Texas Instruments CC2538 devices with Z-Stack 3.0.1.
5
How can I fix this vulnerability?
To fix this vulnerability, update the Z-Stack software to a version that properly processes the ZCL Read Reporting Configuration Response message.