VYPR

Vendor CVEs

Silabs.com

All CVEs

148 total · sorted by risk
  • CVE-2023-39540MedFeb 20, 2024
    risk 0.38cvss 5.9epss 0.01

    A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…

  • CVE-2023-3024MedSep 29, 2023
    risk 0.38cvss 5.9epss 0.00

    Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

  • CVE-2023-5310MedDec 15, 2023
    risk 0.37cvss 5.7epss 0.00

    A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.

  • CVE-2022-24939MedNov 18, 2022
    risk 0.37cvss 5.7epss 0.00

     A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

  • CVE-2024-4013MedJun 6, 2024
    risk 0.36cvss 5.6epss 0.00

    A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity…

  • CVE-2026-14366MedAug 31, 2026
    risk 0.35cvss 6.4epss 0.00

    The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack; the driver only borrows it to copy the frame bytes into a…

  • CVE-2024-6350MedJan 8, 2025
    risk 0.35cvss 6.5epss 0.00

    A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.

  • CVE-2026-65933MedAug 13, 2026
    risk 0.34cvss —epss 0.00

    A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.

  • CVE-2026-65932MedAug 13, 2026
    risk 0.34cvss —epss 0.00

    The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.

  • CVE-2025-10933MedJan 5, 2026
    risk 0.34cvss —epss 0.00

    An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.

  • CVE-2025-2329MedJul 25, 2025
    risk 0.34cvss —epss 0.00

    In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and may send a corrupt packet over SPI to its host,  causing the host to reset the RCP which results in a denial of service.

  • CVE-2023-51394MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

  • CVE-2023-51393MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the…

  • CVE-2023-2683MedJun 15, 2023
    risk 0.34cvss 5.3epss 0.00

    A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

  • CVE-2023-32100MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32099MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32098MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2481MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-1132MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2024-50931MedDec 10, 2024
    risk 0.30cvss 4.6epss 0.00

    Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

  • CVE-2023-41097MedDec 21, 2023
    risk 0.30cvss 4.6epss 0.00

    An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

  • CVE-2024-23937MedJan 31, 2025
    risk 0.28cvss 4.3epss 0.00

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from…

  • CVE-2024-6351MedJan 28, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

  • CVE-2024-6352MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

  • CVE-2024-9055MedMar 17, 2025
    risk 0.27cvss 4.2epss 0.00

    The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.

  • CVE-2023-3488LowJul 28, 2023
    risk 0.25cvss 3.8epss 0.00

    Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

  • CVE-2024-10106LowJan 9, 2025
    risk 0.24cvss 3.7epss 0.00

    A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

  • CVE-2023-0969LowJun 21, 2023
    risk 0.23cvss 3.5epss 0.00

    A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.

  • CVE-2023-41093LowJul 12, 2024
    risk 0.20cvss 3.1epss 0.00

    Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

  • CVE-2023-2747LowJun 15, 2023
    risk 0.20cvss 3.1epss 0.00

    The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.

  • CVE-2023-32097LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32096LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-0965LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2687LowJun 2, 2023
    risk 0.19cvss 2.9epss 0.00

    Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.

  • CVE-2026-15418LowSep 10, 2026
    risk 0.16cvss —epss 0.00

    In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

  • CVE-2025-14055LowFeb 20, 2026
    risk 0.16cvss —epss 0.00

    An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a specially crafted packet.

  • CVE-2025-14547LowFeb 20, 2026
    risk 0.15cvss —epss 0.00

    An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.

  • CVE-2024-2502LowAug 29, 2024
    risk 0.13cvss 2.0epss 0.00

    An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper reset) occurs. This…

  • CVE-2025-7432LowFeb 9, 2026
    risk 0.07cvss —epss 0.00

    DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an attacker to eventually extract secret keys through a DPA attack.

  • CVE-2025-3301LowApr 29, 2025
    risk 0.07cvss —epss 0.00

    DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The…

  • CVE-2024-12975LowMar 7, 2025
    risk 0.07cvss —epss 0.00

    A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.

  • CVE-2026-6432MedJun 25, 2026
    risk 0.00cvss —epss 0.00

    Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

  • CVE-2026-4526MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47153MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

  • CVE-2026-47147HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…

  • CVE-2026-47146MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-47145MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-2815HigJun 25, 2026
    risk 0.00cvss —epss 0.00

    Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Page 3 of 3