Skip to main content

Vendor archive

silabs CVEs

Beta · best-effort

96 CVEs tagged to vendor silabs16 Critical, 31 High, 41 Medium, 8 Low, 0 Unrated.

CVE-2020-27630

Published Oct 10, 2023

In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41094

Published Oct 4, 2023

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a devi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4041

Published Aug 23, 2023

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloade…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0972

Published Jun 21, 2023

Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary cod…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-0971

Published Jun 21, 2023

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be rec…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-0970

Published Jun 21, 2023

Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to ov…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0969

Published Jun 21, 2023

A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global m…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2686

Published Jun 15, 2023

Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-32100

Published May 18, 2023

Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32097

Published May 18, 2023

Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32096

Published May 18, 2023

Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2481

Published May 18, 2023

Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1132

Published May 18, 2023

Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0965

Published May 18, 2023

Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-0775

Published Mar 28, 2023

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 96 CVEsPage 3 of 4