CVE-2019-15913
Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- mi/dgnwg03lm firmware · mi/zncz03lm firmware · mi/mccgq01lm firmware · mi/wsdcgq01lm firmware · mi/rtcgq01lm firmware
- Source
- cve@mitre.org
References
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15913.mdExploit, Third Party Advisory
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15913.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.