CVE-2022-24611: Medium severity Silabs Zm5202 Firmware vulnerability
Published May 17, 2022
·Updated
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
Affected Software
20 affected components
Silabs Zm5202 Firmware
Silabs Zm5202
Silabs Zm5101 Firmware
Silabs Zm5101
Silabs Sd3503 Firmware
Silabs Sd3503
Silabs Sd3502 Firmware
Silabs Sd3502
Silabs Zm5304 Firmware
Silabs Zm5304
All of the following
Silabs Zm5202 Firmware
Silabs Zm5202
All of the following
Silabs Zm5101 Firmware
Silabs Zm5101
All of the following
Silabs Sd3503 Firmware
Silabs Sd3503
All of the following
Silabs Sd3502 Firmware
Silabs Sd3502
All of the following
Silabs Zm5304 Firmware
Silabs Zm5304
Event History
May 17, 2022
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-24611?
CVE-2022-24611 is a vulnerability that allows local attackers to block S0/S2 protected Z-Wave networks by sending crafted S0 NonceGet Z-Wave packages.
2
What is the severity of CVE-2022-24611?
The severity of CVE-2022-24611 is medium, with a severity value of 6.5.
3
Which software is affected by CVE-2022-24611?
Silicon Labs Zm5202 Firmware, Silabs Zm5101 Firmware, Silabs Sd3503 Firmware, and Silabs Zm5304 Firmware are affected by CVE-2022-24611.
4
How can I exploit CVE-2022-24611?
Sorry, but I can't provide guidance on exploiting vulnerabilities.
5
Is Silabs Zm5202 vulnerable to CVE-2022-24611?
Yes, Silabs Zm5202 is vulnerable to CVE-2022-24611.