EmberZNet
by Silabs.com
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41094 | Cri | 0.65 | 10.0 | 0.01 | Oct 4, 2023 | TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet… | ||
| CVE-2023-6874 | Hig | 0.49 | 7.5 | 0.00 | Feb 5, 2024 | Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number | ||
| CVE-2022-24937 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2022 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers. | ||
| CVE-2023-51392 | Med | 0.40 | 6.2 | 0.00 | Feb 23, 2024 | Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks. | ||
| CVE-2025-1394 | Med | 0.38 | — | 0.00 | Jul 30, 2025 | The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS). |
- risk 0.65cvss 10.0epss 0.01
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…
- risk 0.49cvss 7.5epss 0.00
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
- risk 0.42cvss 6.5epss 0.01
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.
- risk 0.40cvss 6.2epss 0.00
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
- risk 0.38cvss —epss 0.00
The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).