Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gecko Software Development Kit HIGH 7.5
CVE-2023-0965

Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key m…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-1132

Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material …

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-2481

Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material …

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-32096

Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier result…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-32097

Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier result…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-32098

Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-32099

Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplica…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit HIGH 7.5
CVE-2023-32100

Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material dup…

Fix: after 4.2.1
Fix from $1,950 2023-05-18
Gecko Software Development Kit MEDIUM 6.5
CVE-2023-0775

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection …

Mitigation only
Fix from $1,600 2023-03-28
Wi Sun Software Development Kit MEDIUM 5.3
CVE-2023-1261

Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.

Fix: after 1.5.0
Fix from $1,600 2023-03-21
Wireless Smart Ubiquitous Network Linux Border Router Firmware MEDIUM 5.3
CVE-2023-1262

Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through ne…

Fix: after 1.5.2
Fix from $1,600 2023-03-21
Gecko Software Development Kit MEDIUM 6.5
CVE-2022-24939

 A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to …

Mitigation only
Fix from $1,600 2022-11-18
Micrium Uc Http CRITICAL 9.8
CVE-2022-24942

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

No fix yet
Fix from $2,300 2022-11-15
Emberznet CRITICAL 9.8
CVE-2022-24937

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

No fix yet
Fix from $2,300 2022-11-14
Emberznet HIGH 7.5
CVE-2022-24938

A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

Mitigation only
Fix from $1,950 2022-11-14
Gecko Bootloader CRITICAL 9.1
CVE-2022-24936

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decr…

Fix: after 4.0.1
Fix from $2,300 2022-11-02
Zm5202 Firmware MEDIUM 6.5
CVE-2022-24611

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 prot…

Mitigation only
Fix from $1,600 2022-05-17
Micrium Os MEDIUM 6.5
CVE-2021-27411

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. Th…

Fix: after 5.10.1
Fix from $1,600 2022-05-03
Zgm130s037hgn Firmware HIGH 8.3
CVE-2013-20003

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an at…

No fix yet
Fix from $1,950 2022-02-04
Zgm130s037hgn Firmware HIGH 8.1
CVE-2018-25029

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range du…

No fix yet
Fix from $1,950 2022-02-04
500 Series Firmware HIGH 8.1
CVE-2020-9058

Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3…

Mitigation only
Fix from $1,950 2022-01-10
500 Series Firmware MEDIUM 6.5
CVE-2020-9059

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to batt…

Mitigation only
Fix from $1,600 2022-01-10
500 Series Firmware MEDIUM 6.5
CVE-2020-9060

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 versio…

Mitigation only
Fix from $1,600 2022-01-10
Uzb 7 MEDIUM 6.5
CVE-2020-10137

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a rem…

Mitigation only
Fix from $1,600 2022-01-10
Iwrap MEDIUM 6.5
CVE-2021-31609

The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greate…

Fix: after 6.3.0
Fix from $1,600 2021-09-07
Micrium Uc Http HIGH 7.5
CVE-2020-13582

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to de…

No fix yet
Fix from $1,950 2021-01-26
Bluetooth Low Energy Software Development Kit HIGH 8.8
CVE-2020-15531

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerabilit…

Fix: 2.13.3.0+
Fix from $1,950 2020-08-20
Bluetooth Low Energy Software Development Kit MEDIUM 6.5
CVE-2020-15532

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in…

Fix: 2.13.3.0+
Fix from $1,600 2020-08-20
Z Wave S0 Firmware MEDIUM 6.5
CVE-2018-19983

An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC…

Mitigation only
Fix from $1,600 2018-12-09