Unrated severityNVD Advisory· Published Oct 4, 2023· Updated Sep 26, 2024
Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet
CVE-2023-41094
Description
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration
This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected
Affected products
2>=7.1.3 <=7.1.5; >=7.2.0 <=7.2.3+ 1 more
- (no CPE)range: >=7.1.3 <=7.1.5; >=7.2.0 <=7.2.3
- (no CPE)range: 7.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.