CVE-2020-9058: High severity Silabs 500 Series Firmware vulnerability
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9058?
CVE-2020-9058 is a vulnerability that affects Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including several specific models.
What is the severity of CVE-2020-9058?
CVE-2020-9058 has a severity score of 8.1, which is considered high.
Which Z-Wave devices are affected by CVE-2020-9058?
Z-Wave devices such as the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05 are affected by CVE-2020-9058.
Does CVE-2020-9058 exploit encryption or replay protection?
No, Z-Wave devices affected by CVE-2020-9058 do not implement encryption or replay protection.
How can I mitigate the CVE-2020-9058 vulnerability?
To mitigate the CVE-2020-9058 vulnerability, it is recommended to apply any firmware updates or patches provided by the manufacturer of the affected Z-Wave devices.