9.8

CVE-2019-15911

Exploit

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AsusHg100 Firmware Version-
   AsusHg100 Version-
AsusMw100 Firmware Version-
   AsusMw100 Version-
AsusWs-101 Firmware Version-
   AsusWs-101 Version-
AsusTs-101 Firmware Version-
   AsusTs-101 Version-
AsusAs-101 Firmware Version-
   AsusAs-101 Version-
AsusMs-101 Firmware Version-
   AsusMs-101 Version-
AsusDl-101 Firmware Version-
   AsusDl-101 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.701
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.