← Back

CVE-2018-25029

nvd nist
Published: Feb 4, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.

Affected (5)

5 products
Zgm130s037hgn Firmware
Zm5202 Firmware
Zm5101 Firmware
Zgm2305a27hgn Firmware
Zgm230sb27hgn Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version s2
Running on/withPlatform Versions
Silabs
Zgm130s037hgn
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version s2
Running on/withPlatform Versions
Silabs
Zm5202
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version s2
Running on/withPlatform Versions
Silabs
Zm5101
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version s2
Running on/withPlatform Versions
Silabs
Zgm2305a27hgn
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version s2
Running on/withPlatform Versions
Silabs
Zgm230sb27hgn
All versions

Timeline

No history available yet.