CVE-2022-24611

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
References
Link Resource
http://z-wave.com Not Applicable
https://github.com/ITSecLab-HSEL/CVE-2022-24611 Third Party Advisory
http://z-wave.com Not Applicable
https://github.com/ITSecLab-HSEL/CVE-2022-24611 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:silabs:zm5202_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zm5202:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:silabs:zm5101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zm5101:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:silabs:sd3503_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:sd3503:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:silabs:sd3502_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:sd3502:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:silabs:zm5304_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zm5304:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:50

Type Values Removed Values Added
References () http://z-wave.com - Not Applicable () http://z-wave.com - Not Applicable
References () https://github.com/ITSecLab-HSEL/CVE-2022-24611 - Third Party Advisory () https://github.com/ITSecLab-HSEL/CVE-2022-24611 - Third Party Advisory

Information

Published : 2022-05-17 18:15

Updated : 2024-11-21 06:50


NVD link : CVE-2022-24611

Mitre link : CVE-2022-24611

CVE.ORG link : CVE-2022-24611


JSON object : View

Products Affected

silabs

  • zm5304
  • sd3502_firmware
  • sd3503
  • sd3502
  • zm5101_firmware
  • zm5304_firmware
  • zm5202
  • zm5101
  • sd3503_firmware
  • zm5202_firmware