7.5

CVE-2019-15915

Exploit

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

Data is provided by the National Vulnerability Database (NVD)
MiDgnwg03lm Firmware Version-
   MiDgnwg03lm Version-
MiZncz03lm Firmware Version-
   MiZncz03lm Version-
MiMccgq01lm Firmware Version-
   MiMccgq01lm Version-
MiRtcgq01lm Firmware Version-
   MiRtcgq01lm Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.616
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.