VYPR

Vendor CVEs

Silabs.com

All CVEs

143 total · sorted by risk
  • CVE-2024-4013MedJun 6, 2024
    risk 0.36cvss 5.6epss 0.00

    A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity…

  • CVE-2024-6350MedJan 8, 2025
    risk 0.35cvss 6.5epss 0.00

    A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.

  • CVE-2026-65933MedAug 13, 2026
    risk 0.34cvss epss 0.00

    A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.

  • CVE-2026-65932MedAug 13, 2026
    risk 0.34cvss epss 0.00

    The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.

  • CVE-2025-10933MedJan 5, 2026
    risk 0.34cvss epss 0.00

    An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.

  • CVE-2025-2329MedJul 25, 2025
    risk 0.34cvss epss 0.00

    In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and may send a corrupt packet over SPI to its host,  causing the host to reset the RCP which results in a denial of service.

  • CVE-2023-51394MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

  • CVE-2023-51393MedFeb 23, 2024
    risk 0.34cvss 5.3epss 0.01

    Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the…

  • CVE-2023-2683MedJun 15, 2023
    risk 0.34cvss 5.3epss 0.00

    A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

  • CVE-2023-32100MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32099MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32098MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2481MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-1132MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2024-50931MedDec 10, 2024
    risk 0.30cvss 4.6epss 0.00

    Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

  • CVE-2023-41097MedDec 21, 2023
    risk 0.30cvss 4.6epss 0.00

    An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

  • CVE-2024-23937MedJan 31, 2025
    risk 0.28cvss 4.3epss 0.00

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from…

  • CVE-2024-6351MedJan 28, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

  • CVE-2024-6352MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.00

    A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

  • CVE-2024-9055MedMar 17, 2025
    risk 0.27cvss 4.2epss 0.00

    The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.

  • CVE-2023-3488LowJul 28, 2023
    risk 0.25cvss 3.8epss 0.00

    Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

  • CVE-2024-10106LowJan 9, 2025
    risk 0.24cvss 3.7epss 0.00

    A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

  • CVE-2023-0969LowJun 21, 2023
    risk 0.23cvss 3.5epss 0.00

    A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.

  • CVE-2023-41093LowJul 12, 2024
    risk 0.20cvss 3.1epss 0.00

    Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

  • CVE-2023-2747LowJun 15, 2023
    risk 0.20cvss 3.1epss 0.00

    The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.

  • CVE-2023-32097LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32096LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-0965LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2687LowJun 2, 2023
    risk 0.19cvss 2.9epss 0.00

    Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.

  • CVE-2025-14055LowFeb 20, 2026
    risk 0.16cvss epss 0.00

    An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a specially crafted packet.

  • CVE-2025-14547LowFeb 20, 2026
    risk 0.15cvss epss 0.00

    An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.

  • CVE-2024-2502LowAug 29, 2024
    risk 0.13cvss 2.0epss 0.00

    An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper reset) occurs. This…

  • CVE-2025-7432LowFeb 9, 2026
    risk 0.07cvss epss 0.00

    DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an attacker to eventually extract secret keys through a DPA attack.

  • CVE-2025-3301LowApr 29, 2025
    risk 0.07cvss epss 0.00

    DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confidential information. The…

  • CVE-2024-12975LowMar 7, 2025
    risk 0.07cvss epss 0.00

    A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.

  • CVE-2026-6924HigJul 23, 2026
    risk 0.00cvss epss 0.00

    A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

  • CVE-2026-6432MedJun 25, 2026
    risk 0.00cvss epss 0.00

    Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

  • CVE-2026-4526MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47153MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

  • CVE-2026-47147HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…

  • CVE-2026-47146MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-47145MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-2815HigJun 25, 2026
    risk 0.00cvss epss 0.00

    Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Page 3 of 3