Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://kb.cert.org/vuls/id/142629 | third party advisory us government resource |
https://ieeexplore.ieee.org/document/9663293 | broken link |
https://github.com/CNK2100/VFuzz-public | third party advisory |
https://doi.org/10.1109/ACCESS.2021.3138768 | broken link |
https://www.kb.cert.org/vuls/id/142629 | third party advisory us government resource |