VYPR

Vendor CVEs

Silabs.com

All CVEs

143 total · sorted by risk
  • CVE-2025-10693HigOct 31, 2025
    risk 0.49cvss epss 0.00

    When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1.

  • CVE-2024-24731HigJan 31, 2025
    risk 0.49cvss 7.5epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the http_download command. The…

  • CVE-2024-8361HigJan 7, 2025
    risk 0.49cvss 7.5epss 0.00

    In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device will restart after watch dog expires. If…

  • CVE-2024-3043HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.

  • CVE-2023-51391HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially allowing a device crash and Denial of Service.

  • CVE-2023-6874HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

  • CVE-2023-6387HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

  • CVE-2026-3290HigMay 14, 2026
    risk 0.48cvss epss 0.00

    Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values

  • CVE-2025-10285HigDec 4, 2025
    risk 0.48cvss epss 0.00

    The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.

  • CVE-2026-65934HigAug 13, 2026
    risk 0.46cvss epss 0.00

    An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.

  • CVE-2025-4321HigNov 17, 2025
    risk 0.46cvss epss 0.00

    In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation

  • CVE-2023-0970HigJun 21, 2023
    risk 0.46cvss 7.1epss 0.00

    Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.

  • CVE-2024-22473MedFeb 21, 2024
    risk 0.44cvss 6.8epss 0.00

    TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

  • CVE-2023-5138MedJan 3, 2024
    risk 0.44cvss 6.8epss 0.00

    Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

  • CVE-2023-41096MedOct 26, 2023
    risk 0.44cvss 6.8epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

  • CVE-2023-41095MedOct 26, 2023
    risk 0.44cvss 6.8epss 0.00

    Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

  • CVE-2025-12131MedFeb 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

  • CVE-2025-2838MedMar 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit…

  • CVE-2024-7137MedDec 19, 2024
    risk 0.42cvss 6.5epss 0.00

    The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device.

  • CVE-2024-50928MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.

  • CVE-2024-50924MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.

  • CVE-2024-50921MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.

  • CVE-2024-3017MedJun 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary…

  • CVE-2023-6640MedFeb 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

  • CVE-2023-6533MedFeb 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC…

  • CVE-2024-0240MedFeb 15, 2024
    risk 0.42cvss 6.5epss 0.00

    A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.

  • CVE-2023-4489MedDec 14, 2023
    risk 0.42cvss 6.4epss 0.01

    The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0…

  • CVE-2023-0775MedMar 28, 2023
    risk 0.42cvss 6.5epss 0.00

    An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

  • CVE-2022-24938MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2022-24937MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

  • CVE-2022-24611MedMay 17, 2022
    risk 0.42cvss 6.5epss 0.01

    Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.

  • CVE-2021-27411MedMay 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small…

  • CVE-2020-9061MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed…

  • CVE-2020-9060MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of…

  • CVE-2020-9059MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 version 3.42 door lock is vulnerable and fails open at a low battery level.

  • CVE-2020-10137MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the…

  • CVE-2021-31609MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing attackers in radio range to trigger a crash in WT32i via a crafted LMP packet.

  • CVE-2020-15532MedAug 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

  • CVE-2024-50929MedDec 10, 2024
    risk 0.40cvss 6.2epss 0.00

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).

  • CVE-2023-51392MedFeb 23, 2024
    risk 0.40cvss 6.2epss 0.00

    Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

  • CVE-2026-0619MedFeb 12, 2026
    risk 0.39cvss epss 0.00

    A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

  • CVE-2025-12986MedDec 4, 2025
    risk 0.39cvss epss 0.00

    When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service triggered by a malformed packet. The device may recover automatically or require a hard reset.

  • CVE-2025-1394MedJul 30, 2025
    risk 0.38cvss epss 0.00

    The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).

  • CVE-2025-1221MedJul 30, 2025
    risk 0.38cvss epss 0.00

    A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host system (CPCd) due to heavy Zigbee traffic, resulting in a Denial of Service (DoS) attack, Only hard reset will bring the device to normal operation

  • CVE-2024-7322MedJan 15, 2025
    risk 0.38cvss 5.8epss 0.00

    A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established

  • CVE-2023-39541MedFeb 20, 2024
    risk 0.38cvss 5.9epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-39540MedFeb 20, 2024
    risk 0.38cvss 5.9epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-3024MedSep 29, 2023
    risk 0.38cvss 5.9epss 0.00

    Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

  • CVE-2023-5310MedDec 15, 2023
    risk 0.37cvss 5.7epss 0.00

    A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.

  • CVE-2022-24939MedNov 18, 2022
    risk 0.37cvss 5.7epss 0.00

     A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.