Z Wave Software Development Kit
Vendor:
First CVE: Dec 15, 2023 · Active for 2 years
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Z Wave Software Development Kit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2023
2 years ago
Most Recent CVE
Dec 10, 2024
593 days ago
CVE Severity & Scoring
Z Wave Software Development Kit8 CVEs
75%
25%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network6 (75.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50930HIGH An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code. | Dec 10, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-50920HIGH Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets. | Dec 10, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-5310MEDIUM A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be ca | Dec 15, 2023 | 6.5 | 22 | NO | NO |
CVE-2024-50929MEDIUM Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denia | Dec 10, 2024 | 6.2 | 18 | NO | NO |
CVE-2024-50928MEDIUM Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the de | Dec 10, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-50924MEDIUM Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via rep | Dec 10, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-50921MEDIUM Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the con | Dec 10, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-50931MEDIUM Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions. | Dec 10, 2024 | 4.6 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Z Wave Software Development Kit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.84.0 | 2 | 6.7 | 0.3% | 0 | 0 |