« Volver al listado

CVE-2020-9061

Estado: ModificadaMedia (6.5)—

Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9061",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "ZooZ",
          "product": "ZST10",
          "versions": [
            {
              "status": "affected",
              "version": "6.04"
            }
          ]
        },
        {
          "vendor": "Silicon Labs",
          "product": "500 series",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "vendor": "Silicon Labs",
          "product": "700 series",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "vendor": "Silicon Labs",
          "product": "UZB-7",
          "versions": [
            {
              "status": "affected",
              "version": "7.00"
            }
          ]
        },
        {
          "vendor": "Samsung",
          "product": "STH-ETH-200",
          "versions": [
            {
              "status": "affected",
              "version": "6.04"
            }
          ]
        },
        {
          "vendor": "Aeon Labs",
          "product": "ZW090-A",
          "versions": [
            {
              "status": "affected",
              "version": "3.95"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-01-10T14:10:16.463",
  "references": [
    {
      "url": "https://doi.org/10.1109/ACCESS.2021.3138768",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/CNK2100/VFuzz-public",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://ieeexplore.ieee.org/document/9663293",
      "tags": [
        "Broken Link"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://kb.cert.org/vuls/id/142629",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/142629",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://doi.org/10.1109/ACCESS.2021.3138768",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CNK2100/VFuzz-public",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ieeexplore.ieee.org/document/9663293",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kb.cert.org/vuls/id/142629",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/142629",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages."
    },
    {
      "lang": "es",
      "value": "Los dispositivos Z-Wave que usan los conjuntos de chips de las series 500 y 700 de Silicon Labs, incluyendo pero sin limitarse a SiLabs UZB-7 versión 7.00, ZooZ ZST10 versión 6.04, Aeon Labs ZW090-A versión 3.95 y Samsung STH-ETH-200 versión 6.04, son susceptibles a una denegación de servicio por medio de mensajes de enrutamiento malformados"
    }
  ],
  "lastModified": "2026-06-17T03:27:25.753",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:aeotec:zw090-a:3.95:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B58B8CF-11BD-402E-8625-4C78629F181E"
            },
            {
              "criteria": "cpe:2.3:o:samsung:sth-eth-200:6.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A7DD561-D129-4D3D-951E-5A55F5304ABC"
            },
            {
              "criteria": "cpe:2.3:o:silabs:uzb-7:7.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C6CE0F9-AB48-4B3D-B1C9-273E09968500"
            },
            {
              "criteria": "cpe:2.3:o:zooz:zst10:6.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DB7F120-CB63-46F6-AC91-8C64BC5D57BC"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:silabs:500_series_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92760285-A1DD-4569-AD71-834BBF2D9E64"
            },
            {
              "criteria": "cpe:2.3:o:silabs:700_series_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C5C81E8-8859-4E66-AF0D-044562F48D60"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}