VYPR

Emberznet

by Silabs

CVEs (17)

  • CVE-2023-41094CriOct 4, 2023
    risk 0.65cvss 10.0epss 0.01

    TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…

  • CVE-2022-24938MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2022-24937MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

  • CVE-2023-51392MedFeb 23, 2024
    risk 0.40cvss 6.2epss 0.00

    Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

  • CVE-2023-51394MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

  • CVE-2023-51393MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the…

  • CVE-2026-4526MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47154MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the…

  • CVE-2026-47153MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

  • CVE-2026-47152MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

  • CVE-2026-47151HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices…

  • CVE-2026-47150HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only…

  • CVE-2026-47149MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47148MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the…

  • CVE-2026-47147HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…

  • CVE-2026-47146MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-47145MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.