community.silabs.com
https://community.silabs.com/068Vm000001NaAM CVE-2023-51393
MEDIUM
Potential DoS due to BusFault and Assert in Ember ZNet legacy packet buffer
Record summary
CVE-2023-51393 has a selected CVSS score of 5.3 (medium).
Description
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
emberznet_sdkBrowse silabs / emberznet_sdkDefault status: unknown | CVE List | Before 7.4.0.0 | affected |
Default status: affected | CVE List | Before 7.4.0.0 | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-51393