CVE-2018-19983

Published: Dic 09, 2018 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2018-11650 Aliases: GSD-2018-19983
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,5
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 6,1
Access Vector: adjacent_network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: complete

Description

AI Translation Available

An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided 'Nonce Get (0x98 0x81)' frames. The reason for dividing the 'Nonce Get' frame is that, in security version S0, when a node receives a 'Nonce Get' frame, the node produces a random new nonce and sends it to the Src node of the received 'Nonce Get' frame. After the nonce value is generated and transmitted, the node transitions to wait mode. At this time, when 'Nonce Get' is received again, the node discards the previous nonce value and generates a random nonce again. Therefore, because the frame is encrypted with previous nonce value, the received normal frame cannot be decrypted.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0008
Percentile
0,2th
Updated

EPSS Score Trend (Last 91 Days)

330

Use of Insufficiently Random Values

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Other Access Control
Potential Impacts:
Other Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Operating System

Z-Wave S0 Firmware by Silabs

cpe:2.3:o:silabs:z-wave_s0_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z-Wave S2 Firmware by Silabs

cpe:2.3:o:silabs:z-wave_s2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/min1233/CVE/blob/master/2
https://github.com/min1233/CVE/blob/master/2