7.5

CVE-2019-15914

Exploit

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

Data is provided by the National Vulnerability Database (NVD)
MiDgnwg03lm Firmware Version-
   MiDgnwg03lm Version-
MiZncz03lm Firmware Version-
   MiZncz03lm Version-
MiMccgq01lm Firmware Version-
   MiMccgq01lm Version-
MiWsdcgq01lm Firmware Version-
   MiWsdcgq01lm Version-
MiRtcgq01lm Firmware Version-
   MiRtcgq01lm Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.616
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.