Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Emberznet MEDIUM 6.5
CVE-2026-4526

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. …

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet HIGH 7.1
CVE-2026-47150

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The…

Fix: after 9.0.2
Fix from $1,950 2026-06-25
Emberznet HIGH 7.1
CVE-2026-47151

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and…

Fix: after 9.0.2
Fix from $1,950 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47149

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47152

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must c…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47153

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must c…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47154

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminat…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet HIGH 7.1
CVE-2026-47147

In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM i…

Fix: after 9.0.2
Fix from $1,950 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47145

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47146

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47148

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate t…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Simplicity Software Development Kit MEDIUM 6.5
CVE-2025-12131

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

Fix: after 2025.6.2
Fix from $1,600 2026-02-05
Gecko Os HIGH 8.8
CVE-2025-2837

Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjace…

Mitigation only
Fix from $1,950 2025-03-26
Gecko Os MEDIUM 6.5
CVE-2025-2838

Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to …

Mitigation only
Fix from $1,600 2025-03-26
Gecko Os HIGH 8.8
CVE-2024-23973

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is …

Mitigation only
Fix from $1,950 2025-01-31
Gecko Os HIGH 8.8
CVE-2024-24731

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is …

Mitigation only
Fix from $1,950 2025-01-31
Z Wave Software Development Kit HIGH 8.8
CVE-2024-50920

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

Fix: after 7.21.1
Fix from $1,950 2024-12-10
Z Wave Software Development Kit HIGH 8.8
CVE-2024-50930

An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2024-12-10
Z Wave Software Development Kit MEDIUM 6.5
CVE-2024-50921

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sen…

Fix: after 7.21.1
Fix from $1,600 2024-12-10
Z Wave Software Development Kit MEDIUM 6.5
CVE-2024-50924

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controlle…

Fix: after 7.21.1
Fix from $1,600 2024-12-10
Z Wave Software Development Kit MEDIUM 6.5
CVE-2024-50928

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in contr…

Fix: after 7.21.1
Fix from $1,600 2024-12-10
Z Wave Software Development Kit MEDIUM 6.2
CVE-2024-50929

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controll…

Fix: after 7.21.1
Fix from $1,600 2024-12-10
Gecko Os HIGH 8.8
CVE-2024-23938

Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent att…

Mitigation only
Fix from $1,950 2024-09-28
Emberznet HIGH 7.5
CVE-2023-51393

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v…

Fix: 7.4.0+
Fix from $1,950 2024-02-23
Emberznet HIGH 7.5
CVE-2023-51394

High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

Fix: 7.4.0+
Fix from $1,950 2024-02-23
Emberznet CRITICAL 9.8
CVE-2023-51392

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of …

Fix: after 7.2.4
Fix from $2,300 2024-02-23
Z Wave Pc Based Controller MEDIUM 6.5
CVE-2023-6533

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the netw…

Fix: after 5.54
Fix from $1,600 2024-02-21
Z Wave Pc Based Controller MEDIUM 6.5
CVE-2023-6640

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

Fix: after 5.54
Fix from $1,600 2024-02-21
Gecko Software Development Kit HIGH 7.5
CVE-2024-22473

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signatur…

Fix: after 4.4.0
Fix from $1,950 2024-02-21
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-45318

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted…

No fix yet
Fix from $2,300 2024-02-20