Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
https://sensepost.com/cms/resources/conferences/2013/bh_zwave/Security%20Evaluation%20of%20Z-Wave_WP.pdf
https://orangecyberdefense.com/global/blog/sensepost/blackhat-conference-z-wave-security/
Source: Mitre, NVD
Published: 2022-02-04
Updated: 2022-02-09
Base Score: 7.9
Vector: CVSS2#AV:A/AC:M/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.3
Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.00141