Turn me on, turn me off: Zigbee assessment in industrial environments
ID: cbfea585-4580-52f5-bac4-04290be132b5
STIX ID: report--cbfea585-4580-52f5-bac4-04290be132b5
Feed Name: Securelist by Kaspersky
This report outlines a practical assessment of Zigbee security in industrial contexts, explaining protocol basics, network roles, and two attack vectors: spoofed packet injection to toggle a relay and coordinator impersonation (rejoin attack) to hijack devices. It details tooling and implementation (nRF52840, Zephyr RTOS, Scapy), key management and decryption (network and link keys, AES-CCM, key derivation), timing constraints, and challenges posed by proprietary profiles. The study concludes with hardening guidance: use installation codes for unique link keys, avoid default/hard-coded keys, and prefer end-to-end application encryption over network-key-only protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
