CVE-2020-27892: High severity ti z-stack vulnerability
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message. It crashes in zclParseInDiscCmdsRspCmd().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27892?
CVE-2020-27892 is a vulnerability in the Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1.
What is the severity of CVE-2020-27892?
The severity of CVE-2020-27892 is high (CVSS score 7.5).
How does CVE-2020-27892 affect Texas Instruments CC2538 devices?
CVE-2020-27892 affects Texas Instruments CC2538 devices with Z-Stack 3.0.1.
What is the impact of CVE-2020-27892?
The impact of CVE-2020-27892 is that it can cause a crash in the zclParseInDiscCmdsRspCmd() function.
How can I fix CVE-2020-27892?
To fix CVE-2020-27892, update the affected software to a version that properly handles the ZCL Discover Commands Received Response message and ZCL Discover Commands Generated Response message.