Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gecko Software Development Kit MEDIUM 6.5
CVE-2024-0240

A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients…

Fix: 4.3.0+
Fix from $1,600 2024-02-15
Gecko Software Development Kit HIGH 7.5
CVE-2023-6874

Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

Fix: 4.4.0+
Fix from $1,950 2024-02-05
Gecko Software Development Kit HIGH 7.5
CVE-2023-6387

A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote …

Fix: 4.4.0+
Fix from $1,950 2024-02-02
Gecko Software Development Kit MEDIUM 6.8
CVE-2023-5138

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

Fix: 4.4.0+
Fix from $1,600 2024-01-03
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-4280

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region …

Fix: after 4.3.2
Fix from $2,300 2024-01-02
Gecko Software Development Kit HIGH 7.5
CVE-2023-41097

An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PK…

Fix: after 4.4.0
Fix from $1,950 2023-12-21
Gecko Software Development Kit CRITICAL 9.1
CVE-2023-4020

An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementatio…

Fix: 4.4.0+
Fix from $2,300 2023-12-15
Z Wave Software Development Kit MEDIUM 6.5
CVE-2023-5310

A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and…

Fix: after 7.20.2.0
Fix from $1,600 2023-12-15
Z\/ip Gateway Sdk CRITICAL 9.8
CVE-2023-4489

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlie…

Fix: after 7.18.03
Fix from $2,300 2023-12-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-31247

A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafte…

No fix yet
Fix from $2,300 2023-11-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-27882

A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially cra…

No fix yet
Fix from $2,300 2023-11-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-28379

A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted netw…

No fix yet
Fix from $2,300 2023-11-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-28391

A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted netwo…

No fix yet
Fix from $2,300 2023-11-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-24585

An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet …

No fix yet
Fix from $2,300 2023-11-14
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-25181

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of ne…

No fix yet
Fix from $2,300 2023-11-14
Openthread Sdk CRITICAL 9.1
CVE-2023-41095

Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modificat…

Fix: after 2.3.1.0
Fix from $2,300 2023-10-26
Emberznet Sdk MEDIUM 6.1
CVE-2023-41096

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modifica…

Fix: after 7.3.1.0
Fix from $1,600 2023-10-26
Gecko Bootloader HIGH 7.8
CVE-2023-3487

An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage…

Fix: after 4.3.1
Fix from $1,950 2023-10-20
Uc\/tcp Ip CRITICAL 9.8
CVE-2020-27630

In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

Mitigation only
Fix from $2,300 2023-10-10
Emberznet CRITICAL 9.8
CVE-2023-41094

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effec…

Fix: after 7.2.3
Fix from $2,300 2023-10-04
Gecko Software Development Kit MEDIUM 6.5
CVE-2023-3024

Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

Fix: 6.0.0+
Fix from $1,600 2023-09-29
Gecko Bootloader CRITICAL 9.8
CVE-2023-4041

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability i…

Fix: 4.2.4 / 4.3.2+
Fix from $2,300 2023-08-23
Gecko Software Development Kit MEDIUM 5.5
CVE-2023-3488

Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

Fix: after 4.3.0
Fix from $1,600 2023-07-28
Z\/ip Gateway Sdk HIGH 8.8
CVE-2023-0972

Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack bu…

Fix: after 7.18.01
Fix from $1,950 2023-06-21
Unify Software Development Kit HIGH 8.8
CVE-2023-3110

Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buf…

Fix: after 1.3.1
Fix from $1,950 2023-06-21
Z\/ip Gateway Sdk HIGH 8.8
CVE-2023-0971

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S…

Fix: after 7.18.01
Fix from $1,950 2023-06-21
Z\/ip Gateway Sdk MEDIUM 6.8
CVE-2023-0970

Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a …

Fix: after 7.18.01
Fix from $1,600 2023-06-21
Bluetooth Low Energy Software Development Kit MEDIUM 6.5
CVE-2023-2683

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate c…

Fix: after 5.1.1
Fix from $1,600 2023-06-15
Gecko Software Development Kit MEDIUM 5.5
CVE-2023-2747

The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.

Fix: 2.2.1+
Fix from $1,600 2023-06-15
Gecko Software Development Kit CRITICAL 9.8
CVE-2023-2686

Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto th…

Fix: after 4.2.3
Fix from $2,300 2023-06-15