Lucene search

K

Z-wave S0 Security Vulnerabilities

cve
cve

CVE-2018-25029

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof...

8.1CVSS

7.9AI Score

0.003EPSS

2022-02-04 11:15 PM
47
cve
cve

CVE-2013-20003

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave...

8.3CVSS

7.9AI Score

0.003EPSS

2022-02-04 11:15 PM
31
cve
cve

CVE-2018-19982

An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The prerequisite is that the attacker is on the same network as the target H...

5.3CVSS

5.2AI Score

0.001EPSS

2018-12-09 07:29 PM
19
cve
cve

CVE-2018-19983

An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously...

6.5CVSS

6.4AI Score

0.001EPSS

2018-12-09 07:29 PM
26