CVE-2013-20003 describes a critical vulnerability in Z-Wave devices from Sierra Designs and Silicon Labs (specifically those using S0 security), where a shared, all-zero network key can be exploited. An attacker within radio range can leverage this weakness to spoof Z-Wave traffic, leading to high impacts on confidentiality, integrity, and availability. With a CVSS score of 8.3 (HIGH), this vulnerability is remotely exploitable with high attack complexity, but does not require user interaction. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
s2CPE matchmatch criteria | cpe:2.3:o:silabs:zgm130s037hgn_firmware:s2:*:*:*:*:*:*:* | ||
s2CPE matchmatch criteria | cpe:2.3:o:silabs:zm5202_firmware:s2:*:*:*:*:*:*:* | ||
s2CPE matchmatch criteria | cpe:2.3:o:silabs:zm5101_firmware:s2:*:*:*:*:*:*:* | ||
s2CPE matchmatch criteria | cpe:2.3:o:silabs:zgm2305a27hgn_firmware:s2:*:*:*:*:*:*:* | ||
s2CPE matchmatch criteria | cpe:2.3:o:silabs:zgm230sb27hgn_firmware:s2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.