Learn about CVE-2020-9059, a vulnerability affecting Z-Wave devices with Silicon Labs 500 series chipsets, leading to uncontrolled resource consumption and battery exhaustion. Find mitigation steps and preventive measures.
Z-Wave devices using Silicon Labs 500 series chipsets are vulnerable to uncontrolled resource consumption, affecting products like Schlage BE468 and Silicon Labs 500 series.
Understanding CVE-2020-9059
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption, leading to battery exhaustion. The Schlage BE468 version 3.42 door lock is an example of a vulnerable device that fails open at a low battery level.
What is CVE-2020-9059?
This CVE identifies a vulnerability in Z-Wave devices that utilize Silicon Labs 500 series chipsets, potentially causing battery depletion due to uncontrolled resource consumption.
The Impact of CVE-2020-9059
The vulnerability can lead to severe consequences, such as devices failing open at critical battery levels, compromising security and functionality.
Technical Details of CVE-2020-9059
Z-Wave devices using Silicon Labs 500 series chipsets are affected by uncontrolled resource consumption, impacting specific products and vendors.
Vulnerability Description
The vulnerability stems from the use of S0 authentication in Z-Wave devices, allowing uncontrolled resource consumption that depletes device batteries.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit the vulnerability by causing uncontrolled resource consumption, leading to battery exhaustion and potential device failure.
Mitigation and Prevention
To address CVE-2020-9059, immediate steps and long-term security practices are essential.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates