VulnerabilityModified
CVE-2019-15914
Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
HIGH 7.5EPSS 1.31%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mi/dgnwg03lm firmware · mi/zncz03lm firmware · mi/mccgq01lm firmware · mi/wsdcgq01lm firmware · mi/rtcgq01lm firmware
- Source
- cve@mitre.org
References
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_1.mdExploit, Third Party Advisory
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_2.mdExploit, Third Party Advisory
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_1.mdExploit, Third Party Advisory
- https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_2.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.