silabs.com Vulnerabilities and Affected Products
Vulnerabilities associated with Simplicity SDK.
Products
Clear product- GSDK12 vulnerabilities
- Gecko Platform10 vulnerabilities
- Simplicity SDK8 vulnerabilities
- Gecko SDK7 vulnerabilities
- WiseConnect7 vulnerabilities
- Ember ZNet SDK6 vulnerabilities
- BT1223 vulnerabilities
- RS9116 Bluetooth SDK3 vulnerabilities
- SiSDK3 vulnerabilities
- Z/IP Gateway SDK3 vulnerabilities
- Ember ZNet2 vulnerabilities
- Gecko Bootloader2 vulnerabilities
- PC Controller2 vulnerabilities
- Bluetooth SDK1 vulnerability
- Configuration Wizard 21 vulnerability
- CP210 VCP Win 2k1 vulnerability
- CP210x VCP Windows1 vulnerability
- EFR32 BLE SDK1 vulnerability
- EmberZNet1 vulnerability
- Flash Programming Utility1 vulnerability
- OpenThread1 vulnerability
- OpenThread SDK1 vulnerability
- RS9116W1 vulnerability
- SE Firmware1 vulnerability
- Series 2 SoCs and associated modules1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-4930HIGH | DPA Countermeasures weakening on Series 3 devicesSYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing). DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gains code execution capability on the impacted device. * Therefore, the keys loaded on SYMCRYPTO may be more vulnerable to extraction through DPA attacks than intended CWE-331Jun 25, 2026 | CVSS7.1v4.0 | EPSS0.101% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8676HIGH | Generated title:Silicon Labs Simplicity SDK Bluetooth LE Bond Deletion and Spoofing Authentication BypassAn attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. CWE-290May 26, 2026 | CVSS8.8v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14972MEDIUM | Insufficient DPA countermeasure reseeding* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability. CWE-331May 15, 2026 | CVSS4.1v4.0 | EPSS0.146% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
ECJ-PAKE Integer Underflow Vulnerability in Silicon Labs PSA Crypto and SE Manager APIsAn integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service. CWE-191Feb 20, 2026 | CVSS2.3v4.0 | EPSS0.278% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
DPA countermeasures not reseeded under certain conditionsDPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an attacker to eventually extract secret keys through a DPA attack. CWE-331Feb 9, 2026 | CVSS1.0v4.0 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-12131MEDIUM | Truncated 802.15.4 packet leads to denial of serviceA truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. | CVSS5.3v4.0 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8414CRITICAL | Zigbee Green Power Host Buffer Overflow VulnerabilityDue to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability. CWE-20Oct 17, 2025 | CVSS9.4v4.0 | EPSS0.255% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6350MEDIUM | EmberZNet malformed MAC layer packet leads to denial of serviceA malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically. CWE-120Jan 8, 2025 | CVSS6.5v3.1 | EPSS0.268% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |