A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Z/ip_gateway_sdk | Silabs | * | 7.18.01 (including) |