Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device
Published Jan 7, 2022
8.8
HIGHCVSS 3.1
EPSS 0.41%
Description
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware upgrades cannot directly address this vulnerability as it is an issue with the Z-Wave specification for these legacy chipsets. One way to protect against this vulnerability is to use 500 or 700 series chipsets that support Security 2 (S2) encryption. As examples, the Linear WADWAZ-1 version 3.43 and WAPIRZ-1 version 3.43 (with 300 series chipsets) are vulnerable.
Affected products
-
- Version 3.43StatusaffectedConstraints-
- Version
-
- Version 3.43StatusaffectedConstraints-
- Version
-
- Version allStatusaffectedConstraints-
- Version
-
- Version allStatusaffectedConstraints-
- Version
-
- Version allStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linear | Wadwaz-1 | n/a |
| ||||||
| Linear | Wapirz-1 | n/a |
| ||||||
| Silicon Labs | 100 Series | n/a |
| ||||||
| Silicon Labs | 200 Series | n/a |
| ||||||
| Silicon Labs | 300 Series | n/a |
|
Configuration 2
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://doi.org/10.1109/ACCESS.2021.3138768 x_refsource_MISCBroken Link
- https://github.com/CNK2100/VFuzz-public x_refsource_MISCThird Party Advisory
- https://ieeexplore.ieee.org/document/9663293 x_refsource_MISCBroken Link
- https://kb.cert.org/vuls/id/142629 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/142629 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://doi.org/10.1109/ACCESS.2021.3138768 | x_refsource_MISCBroken Link | |
| https://github.com/CNK2100/VFuzz-public | x_refsource_MISCThird Party Advisory | |
| https://ieeexplore.ieee.org/document/9663293 | x_refsource_MISCBroken Link | |
| https://kb.cert.org/vuls/id/142629 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| https://www.kb.cert.org/vuls/id/142629 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.