9.8

CVE-2019-15911

Exploit

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.

Data is provided by the National Vulnerability Database (NVD)
AsusHg100 Firmware Version-
   AsusHg100 Version-
AsusMw100 Firmware Version-
   AsusMw100 Version-
AsusWs-101 Firmware Version-
   AsusWs-101 Version-
AsusTs-101 Firmware Version-
   AsusTs-101 Version-
AsusAs-101 Firmware Version-
   AsusAs-101 Version-
AsusMs-101 Firmware Version-
   AsusMs-101 Version-
AsusDl-101 Firmware Version-
   AsusDl-101 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.67% 0.701
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.