VYPR

Ember ZNet stack

by Silabs.com

CVEs (7)

  • CVE-2023-41094CriOct 4, 2023
    risk 0.65cvss 10.0epss 0.01

    TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…

  • CVE-2022-24938MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2022-24937MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

  • CVE-2025-1221MedJul 30, 2025
    risk 0.38cvss epss 0.00

    A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host system (CPCd) due to heavy Zigbee traffic, resulting in a Denial of Service (DoS) attack, Only hard reset will bring the device to normal operation

  • CVE-2022-24939MedNov 18, 2022
    risk 0.37cvss 5.7epss 0.00

     A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2024-6351MedJan 28, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

  • CVE-2024-6352MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert