An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
References
Link | Resource |
---|---|
https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_1.md | Exploit Third Party Advisory |
https://github.com/chengcheng227/CVE-POC/blob/master/CVE-2019-15914_2.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Information
Published : 2019-12-20 09:15
Updated : 2020-01-03 06:59
NVD link : CVE-2019-15914
Mitre link : CVE-2019-15914
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mi
- dgnwg03lm
- zncz03lm
- wsdcgq01lm_firmware
- mccgq01lm_firmware
- rtcgq01lm
- zncz03lm_firmware
- mccgq01lm
- dgnwg03lm_firmware
- wsdcgq01lm
- rtcgq01lm_firmware