VYPR

Simplicity SDK

by Silabs.com

Source repositories

CVEs (9)

  • CVE-2025-7964CriJan 30, 2026
    risk 0.60cvss epss 0.00

    After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to…

  • CVE-2025-12131MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

  • CVE-2024-3017MedJun 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary…

  • CVE-2024-4013MedJun 6, 2024
    risk 0.36cvss 5.6epss 0.00

    A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity…

  • CVE-2024-6350MedJan 8, 2025
    risk 0.35cvss 6.5epss 0.00

    A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.

  • CVE-2025-2329MedJul 25, 2025
    risk 0.34cvss epss 0.00

    In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and may send a corrupt packet over SPI to its host,  causing the host to reset the RCP which results in a denial of service.

  • CVE-2024-10106LowJan 9, 2025
    risk 0.24cvss 3.7epss 0.00

    A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

  • CVE-2023-41093LowJul 12, 2024
    risk 0.20cvss 3.1epss 0.00

    Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

  • CVE-2024-12975LowMar 7, 2025
    risk 0.07cvss epss 0.00

    A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.