Skip to main content

Vendor archive

silabs CVEs

Beta · best-effort

96 CVEs tagged to vendor silabs16 Critical, 31 High, 41 Medium, 8 Low, 0 Unrated.

CVE-2022-24942

Published Nov 15, 2022

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24938

Published Nov 14, 2022

A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24937

Published Nov 14, 2022

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24936

Published Nov 2, 2022

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootl…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27411

Published May 3, 2022

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignmen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25029

Published Feb 4, 2022

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and…

CVSS 8.1 · High

CVE-2013-20003

Published Feb 4, 2022

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to s…

CVSS 8.3 · High

CVE-2020-10137

Published Jan 10, 2022

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31609

Published Sep 7, 2021

The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing atta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13582

Published Jan 26, 2021

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 76-96 of 96 CVEsPage 4 of 4