An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs a factory reset. This causes the bulb to lose configuration information about the Zigbee network and current brightness level. After this attack, all lights are on with full brightness, and a user cannot control the bulbs with either the IKEA Home Smart app or the TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score 7.1 vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SNPS

Published: 2022-10-14T00:00:00

Updated: 2024-08-03T11:10:32.467Z

Reserved: 2022-08-31T00:00:00

Link: CVE-2022-39064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-14T16:15:18.417

Modified: 2022-10-18T20:15:06.010

Link: CVE-2022-39064

cve-icon Redhat

No data.