silabs.com Vulnerabilities and Affected Products
Vulnerabilities associated with Ember ZNet SDK.
Products
Clear product- GSDK12 vulnerabilities
- Gecko Platform10 vulnerabilities
- Simplicity SDK8 vulnerabilities
- Gecko SDK7 vulnerabilities
- WiseConnect7 vulnerabilities
- Ember ZNet SDK6 vulnerabilities
- BT1223 vulnerabilities
- RS9116 Bluetooth SDK3 vulnerabilities
- SiSDK3 vulnerabilities
- Z/IP Gateway SDK3 vulnerabilities
- Ember ZNet2 vulnerabilities
- Gecko Bootloader2 vulnerabilities
- PC Controller2 vulnerabilities
- Bluetooth SDK1 vulnerability
- Configuration Wizard 21 vulnerability
- CP210 VCP Win 2k1 vulnerability
- CP210x VCP Windows1 vulnerability
- EFR32 BLE SDK1 vulnerability
- EmberZNet1 vulnerability
- Flash Programming Utility1 vulnerability
- OpenThread1 vulnerability
- OpenThread SDK1 vulnerability
- RS9116W1 vulnerability
- SE Firmware1 vulnerability
- Series 2 SoCs and associated modules1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Ember ZNet buffer overflow in 'packet handoff' pluginA buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer. CWE-120Jan 9, 2025 | CVSS3.7v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-3043HIGH | Zigbee co-ordinator realignment packet may lead to denial of serviceAn unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification. CWE-829Jun 27, 2024 | CVSS7.5v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51393MEDIUM | Potential DoS due to BusFault and Assert in Ember ZNet legacy packet bufferDue to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network. | CVSS5.3v3.1 | EPSS0.515% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51394MEDIUM | Potential DoS for EFR32xxx parts in high traffic environments due to null buffer dereference / crashHigh traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash. CWE-476Feb 23, 2024 | CVSS5.3v3.1 | EPSS0.515% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51392MEDIUM | Silicon Labs EFR32xxx parts with classic key storage do not use hardware accelerated AES-CCMEmber ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks. | CVSS6.2v3.1 | EPSS0.244% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41096MEDIUM | Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet devicesMissing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier. | CVSS6.8v3.1 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |