First published: Tue Oct 27 2020(Updated: )
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message. It crashes in zclParseInDiscCmdsRspCmd().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ti Z-stack | =3.0.1 | |
Ti Cc2538 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27892 is a vulnerability in the Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1.
The severity of CVE-2020-27892 is high (CVSS score 7.5).
CVE-2020-27892 affects Texas Instruments CC2538 devices with Z-Stack 3.0.1.
The impact of CVE-2020-27892 is that it can cause a crash in the zclParseInDiscCmdsRspCmd() function.
To fix CVE-2020-27892, update the affected software to a version that properly handles the ZCL Discover Commands Received Response message and ZCL Discover Commands Generated Response message.