CVE-2020-9057
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware upgrades cannot directly address this vulnerability as it is an issue with the Z-Wave specification for these legacy chipsets. One way to protect against this vulnerability is to use 500 or 700 series chipsets that support Security 2 (S2) encryption. As examples, the Linear WADWAZ-1 version 3.43 and WAPIRZ-1 version 3.43 (with 300 series chipsets) are vulnerable.
EPSS 0.41% · 34.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linear | wadwaz-1 | 3.43 |
| Linear | WADWAZ-1 | 3.43 |
| Silicon Labs | 300 series | all |
| Linear | WAPIRZ-1 | 3.43 |
| silabs | 300_series_firmware | |
| Silicon Labs | 100 series | * |
| Silicon Labs | 200 series | * |
| silabs | 200_series_firmware | |
| linear | wapirz-1 | 3.43 |
| silabs | 100_series_firmware |
Timeline
- Jan 7, 2022 EPSS Score
- Jan 7, 2022 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 2, 2022 EPSS Score
- Apr 24, 2022 EPSS Score
- Jun 17, 2022 EPSS Score
- Aug 10, 2022 EPSS Score
- Oct 3, 2022 EPSS Score
- Nov 26, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- May 5, 2023 EPSS Score
References
- https://kb.cert.org/vuls/id/142629 third-party-advisory
- https://ieeexplore.ieee.org/document/9663293 url
- https://github.com/CNK2100/VFuzz-public url
- https://doi.org/10.1109/ACCESS.2021.3138768 url
- VU#142629 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-9057 advisory