Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-4526 In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. … Emberznet after 9.0.2 Fix from $1,6002026-06-25 HIGH 7.1 CVE-2026-47150 In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The… Emberznet after 9.0.2 Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-47151 In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and… Emberznet after 9.0.2 Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-47149 In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47152 In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must c… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47153 In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must c… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47154 In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminat… Emberznet after 9.0.2 Fix from $1,6002026-06-25 HIGH 7.1 CVE-2026-47147 In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM i… Emberznet after 9.0.2 Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-47145 In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47146 In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47148 In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate t… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2025-12131 A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. Simplicity Software Development Kit after 2025.6.2 Fix from $1,6002026-02-05 HIGH 8.8 CVE-2025-2837 Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjace… Gecko Os Mitigation only Fix from $1,9502025-03-26 MEDIUM 6.5 CVE-2025-2838 Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to … Gecko Os Mitigation only Fix from $1,6002025-03-26 HIGH 8.8 CVE-2024-23973 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is … Gecko Os Mitigation only Fix from $1,9502025-01-31 HIGH 8.8 CVE-2024-24731 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is … Gecko Os Mitigation only Fix from $1,9502025-01-31 HIGH 8.8 CVE-2024-50920 Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets. Z Wave Software Development Kit after 7.21.1 Fix from $1,9502024-12-10 HIGH 8.8 CVE-2024-50930 An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code. Z Wave Software Development Kit No fix yet Fix from $1,9502024-12-10 MEDIUM 6.5 CVE-2024-50921 Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sen… Z Wave Software Development Kit after 7.21.1 Fix from $1,6002024-12-10 MEDIUM 6.5 CVE-2024-50924 Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controlle… Z Wave Software Development Kit after 7.21.1 Fix from $1,6002024-12-10 MEDIUM 6.5 CVE-2024-50928 Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in contr… Z Wave Software Development Kit after 7.21.1 Fix from $1,6002024-12-10 MEDIUM 6.2 CVE-2024-50929 Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controll… Z Wave Software Development Kit after 7.21.1 Fix from $1,6002024-12-10 HIGH 8.8 CVE-2024-23938 Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent att… Gecko Os Mitigation only Fix from $1,9502024-09-28 HIGH 7.5 CVE-2023-51393 Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v… Emberznet 7.4.0+ Fix from $1,9502024-02-23 HIGH 7.5 CVE-2023-51394 High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash. Emberznet 7.4.0+ Fix from $1,9502024-02-23 CRITICAL 9.8 CVE-2023-51392 Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of … Emberznet after 7.2.4 Fix from $2,3002024-02-23 MEDIUM 6.5 CVE-2023-6533 Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the netw… Z Wave Pc Based Controller after 5.54 Fix from $1,6002024-02-21 MEDIUM 6.5 CVE-2023-6640 Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier. Z Wave Pc Based Controller after 5.54 Fix from $1,6002024-02-21 HIGH 7.5 CVE-2024-22473 TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signatur… Gecko Software Development Kit after 4.4.0 Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2023-45318 A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted… Gecko Software Development Kit No fix yet Fix from $2,3002024-02-20