VYPR

Vendor CVEs

Silabs.com

All CVEs

113 total · sorted by risk
  • CVE-2024-50930Dec 10, 2024
    risk 0.00cvss epss 0.00

    An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

  • CVE-2024-23938Sep 28, 2024
    risk 0.00cvss epss 0.01

    Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit…

  • CVE-2023-41093Jul 12, 2024
    risk 0.00cvss epss 0.00

    Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

  • CVE-2023-51393Feb 23, 2024
    risk 0.00cvss epss 0.01

    Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the…

  • CVE-2023-51394Feb 23, 2024
    risk 0.00cvss epss 0.01

    High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

  • CVE-2023-51392Feb 23, 2024
    risk 0.00cvss epss 0.00

    Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

  • CVE-2024-22473Feb 21, 2024
    risk 0.00cvss epss 0.00

    TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

  • CVE-2023-39541Feb 20, 2024
    risk 0.00cvss epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-39540Feb 20, 2024
    risk 0.00cvss epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-45318Feb 20, 2024
    risk 0.00cvss epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2024-0240Feb 15, 2024
    risk 0.00cvss epss 0.00

    A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.

  • CVE-2023-6874Feb 5, 2024
    risk 0.00cvss epss 0.00

    Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

  • CVE-2023-6387Feb 2, 2024
    risk 0.00cvss epss 0.01

    A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

  • CVE-2023-5138Jan 3, 2024
    risk 0.00cvss epss 0.00

    Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

  • CVE-2023-4280Jan 2, 2024
    risk 0.00cvss epss 0.00

    An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

  • CVE-2023-41097Dec 21, 2023
    risk 0.00cvss epss 0.00

    An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

  • CVE-2023-4020Dec 15, 2023
    risk 0.00cvss epss 0.01

    An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.

  • CVE-2023-5310Dec 15, 2023
    risk 0.00cvss epss 0.00

    A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.

  • CVE-2023-24585Nov 14, 2023
    risk 0.00cvss epss 0.01

    An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-25181Nov 14, 2023
    risk 0.00cvss epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28391Nov 14, 2023
    risk 0.00cvss epss 0.01

    A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-27882Nov 14, 2023
    risk 0.00cvss epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28379Nov 14, 2023
    risk 0.00cvss epss 0.02

    A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-31247Nov 14, 2023
    risk 0.00cvss epss 0.02

    A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-41096Oct 26, 2023
    risk 0.00cvss epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

  • CVE-2023-41095Oct 26, 2023
    risk 0.00cvss epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

  • CVE-2023-3487Oct 20, 2023
    risk 0.00cvss epss 0.00

    An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.

  • CVE-2023-41094Oct 4, 2023
    risk 0.00cvss epss 0.01

    TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…

  • CVE-2023-4041Aug 23, 2023
    risk 0.00cvss epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…

  • CVE-2023-3488Jul 28, 2023
    risk 0.00cvss epss 0.00

    Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

  • CVE-2023-3110Jun 21, 2023
    risk 0.00cvss epss 0.00

    Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0972Jun 21, 2023
    risk 0.00cvss epss 0.00

    Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0971Jun 21, 2023
    risk 0.00cvss epss 0.00

    A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

  • CVE-2023-0970Jun 21, 2023
    risk 0.00cvss epss 0.00

    Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.

  • CVE-2023-0969Jun 21, 2023
    risk 0.00cvss epss 0.00

    A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.

  • CVE-2023-2683Jun 15, 2023
    risk 0.00cvss epss 0.00

    A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

  • CVE-2023-2686Jun 15, 2023
    risk 0.00cvss epss 0.01

    Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

  • CVE-2023-2687Jun 2, 2023
    risk 0.00cvss epss 0.00

    Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.

  • CVE-2023-32100May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32099May 18, 2023
    risk 0.00cvss epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32098May 18, 2023
    risk 0.00cvss epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32097May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32096May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2481May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-1132May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-0965May 18, 2023
    risk 0.00cvss epss 0.00

    Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-1262Mar 21, 2023
    risk 0.00cvss epss 0.00

    Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.

  • CVE-2023-1261Mar 21, 2023
    risk 0.00cvss epss 0.00

    Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.

  • CVE-2022-24939Nov 17, 2022
    risk 0.00cvss epss 0.00

     A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2022-24938Nov 14, 2022
    risk 0.00cvss epss 0.01

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.