CVE-2020-9059

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 version 3.42 door lock is vulnerable and fails open at a low battery level.
References
Link Resource
https://doi.org/10.1109/ACCESS.2021.3138768 Broken Link
https://github.com/CNK2100/VFuzz-public Third Party Advisory
https://ieeexplore.ieee.org/document/9663293 Broken Link
https://kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
https://doi.org/10.1109/ACCESS.2021.3138768 Broken Link
https://github.com/CNK2100/VFuzz-public Third Party Advisory
https://ieeexplore.ieee.org/document/9663293 Broken Link
https://kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/142629 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:o:silabs:500_series_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:schlage:be468:3.42:*:*:*:*:*:*:*

History

21 Nov 2024, 05:39

Type Values Removed Values Added
References () https://doi.org/10.1109/ACCESS.2021.3138768 - Broken Link () https://doi.org/10.1109/ACCESS.2021.3138768 - Broken Link
References () https://github.com/CNK2100/VFuzz-public - Third Party Advisory () https://github.com/CNK2100/VFuzz-public - Third Party Advisory
References () https://ieeexplore.ieee.org/document/9663293 - Broken Link () https://ieeexplore.ieee.org/document/9663293 - Broken Link
References () https://kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource () https://kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource
References () https://www.kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource () https://www.kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource

18 Jan 2022, 17:25

Type Values Removed Values Added
CPE cpe:2.3:o:silabs:500_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schlage:be468:3.42:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.1
v3 : 6.5
CWE CWE-400
References (CERT-VN) https://www.kb.cert.org/vuls/id/142629 - (CERT-VN) https://www.kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource
References (MISC) https://github.com/CNK2100/VFuzz-public - (MISC) https://github.com/CNK2100/VFuzz-public - Third Party Advisory
References (MISC) https://doi.org/10.1109/ACCESS.2021.3138768 - (MISC) https://doi.org/10.1109/ACCESS.2021.3138768 - Broken Link
References (MISC) https://ieeexplore.ieee.org/document/9663293 - (MISC) https://ieeexplore.ieee.org/document/9663293 - Broken Link
References (CERT-VN) https://kb.cert.org/vuls/id/142629 - (CERT-VN) https://kb.cert.org/vuls/id/142629 - Third Party Advisory, US Government Resource

10 Jan 2022, 14:14

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-10 14:10

Updated : 2024-11-21 05:39


NVD link : CVE-2020-9059

Mitre link : CVE-2020-9059

CVE.ORG link : CVE-2020-9059


JSON object : View

Products Affected

silabs

  • 500_series_firmware

schlage

  • be468
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling