CVE-2019-15911

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:hg100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:hg100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:asus:mw100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:mw100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:asus:ws-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ws-101:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:asus:ts-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts-101:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:asus:as-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:as-101:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:asus:ms-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:ms-101:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:asus:dl-101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:asus:dl-101:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:29

Type Values Removed Values Added
References () https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15911.md - Exploit, Third Party Advisory () https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15911.md - Exploit, Third Party Advisory

Information

Published : 2019-12-20 17:15

Updated : 2024-11-21 04:29


NVD link : CVE-2019-15911

Mitre link : CVE-2019-15911

CVE.ORG link : CVE-2019-15911


JSON object : View

Products Affected

asus

  • ms-101_firmware
  • ms-101
  • dl-101
  • as-101_firmware
  • dl-101_firmware
  • hg100
  • ws-101_firmware
  • mw100
  • ws-101
  • ts-101
  • mw100_firmware
  • ts-101_firmware
  • hg100_firmware
  • as-101
CWE
CWE-319

Cleartext Transmission of Sensitive Information