CVE-2024-4013

MEDIUM

Gecko SDK 3.1.0-2024.06.0 - Improper Resource Shutdown or Release in mesh_node_power_off

Title source: llm
STIX 2.1

Description

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioning scheme was changed from Gecko SDK vX.Y.Z to Simplicity SDK YYYY.MM.Patch#.

References (2)

Core 2
Core References
Various Sources vendor-advisory permissions-required
https://community.silabs.com/068Vm000006rR53

Scores

CVSS v3 5.6
EPSS 0.0027
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
silabs.com/Gecko SDK 3.1.0 - 2024.06.0
Published Jun 06, 2024
Tracked Since Feb 18, 2026