VYPR
Vendor

Silabs

Products
38
CVEs
100
Across products
111
Status
Private

Products

38
View all 38 products →

Recent CVEs

100
View all 100 CVEs →
  • CVE-2023-45318CriFeb 20, 2024
    risk 0.65cvss 10.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-41094CriOct 4, 2023
    risk 0.65cvss 10.0epss 0.01

    TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…

  • CVE-2020-27630CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

  • CVE-2023-4041CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…

  • CVE-2023-2686CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

  • CVE-2023-3110CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0972CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0971CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

  • CVE-2023-4280CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

  • CVE-2023-4020CriDec 15, 2023
    risk 0.59cvss 9.0epss 0.01

    An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.

  • CVE-2023-31247CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28391CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.01

    A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28379CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-27882CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-25181CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2022-24942CriNov 15, 2022
    risk 0.59cvss 9.1epss 0.02

    Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

  • CVE-2026-16101HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

  • CVE-2025-2837HigMar 26, 2025
    risk 0.57cvss 8.8epss 0.00

    Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to…

  • CVE-2024-23973HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the handling of HTTP GET requests. The issue…

  • CVE-2024-50930HigDec 10, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.