VDB

CVE-2020-9060

CVE-2020-9060 PUBLISHED CVSS 6.5 MEDIUM

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

EPSS 0.53% · 42.1th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.53%
42.1th percentile

Affected Products

VendorProductVersions
zoozzen205.03
ZooZZEN205.03
FibaroFGWPB-1114.3
aeoteczw090-a3.95
Aeon LabsZW090-A3.95
silabs500_series_firmware
fibarofgwpb-1114.3
ZooZZST106.04
Silicon Labs500 seriesall
zoozzen255.03
ZooZZEN255.03
zoozzst106.04

Timeline

  • Jan 7, 2022 CVE Published
  • Jan 7, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 24, 2022 EPSS Score
  • Jun 17, 2022 EPSS Score
  • Aug 10, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 26, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • May 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›