Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
References
Link | Resource |
---|---|
http://z-wave.com | Not Applicable |
https://github.com/ITSecLab-HSEL/CVE-2022-24611 | Third Party Advisory |
http://z-wave.com | Not Applicable |
https://github.com/ITSecLab-HSEL/CVE-2022-24611 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
21 Nov 2024, 06:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://z-wave.com - Not Applicable | |
References | () https://github.com/ITSecLab-HSEL/CVE-2022-24611 - Third Party Advisory |
26 May 2022, 15:16
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:silabs:zm5202:-:*:*:*:*:*:*:* cpe:2.3:o:silabs:zm5101_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:silabs:zm5202_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:silabs:sd3503_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:silabs:zm5101:-:*:*:*:*:*:*:* cpe:2.3:h:silabs:sd3502:-:*:*:*:*:*:*:* cpe:2.3:o:silabs:zm5304_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:silabs:sd3502_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:silabs:zm5304:-:*:*:*:*:*:*:* cpe:2.3:h:silabs:sd3503:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 6.1
v3 : 6.5 |
CWE | NVD-CWE-noinfo | |
References | (MISC) https://github.com/ITSecLab-HSEL/CVE-2022-24611 - Third Party Advisory | |
References | (MISC) http://z-wave.com - Not Applicable |
17 May 2022, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-05-17 18:15
Updated : 2024-11-21 06:50
NVD link : CVE-2022-24611
Mitre link : CVE-2022-24611
CVE.ORG link : CVE-2022-24611
JSON object : View
Products Affected
silabs
- sd3503
- zm5304
- zm5202_firmware
- sd3502_firmware
- zm5101
- zm5101_firmware
- zm5202
- sd3503_firmware
- sd3502
- zm5304_firmware
CWE