CVE-2024-50920
HIGHDescription
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
Is your site exposed to CVE-2024-50920?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| silabs | z-wave_software_development_kit |
| silabs | efr32zg14p231f256gm32 |
| silabs | efr32zg23a010f512gm40 |
| silabs | efr32zg23a010f512gm48 |
| silabs | efr32zg23a020f512gm40 |
| silabs | efr32zg23a020f512gm48 |
| silabs | efr32zg23b010f512im40 |
| silabs | efr32zg23b010f512im48 |
| silabs | efr32zg23b011f512im40 |
| silabs | efr32zg23b020f512im40 |
| silabs | efr32zg23b020f512im48 |
| silabs | efr32zg23b021f512im40 |
| silabs | zgm130s037hgn |
| silabs | zgm230sa27hgn |
| silabs | zgm230sb27hgn |
References
Frequently Asked Questions
What is CVE-2024-50920? +
How severe is CVE-2024-50920? +
What products are affected by CVE-2024-50920? +
How do I check if I'm vulnerable to CVE-2024-50920? +
Related Vulnerabilities
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …