8.8
CVE-2023-51395
- EPSS 0.06%
- Veröffentlicht 07.03.2024 05:15:53
- Zuletzt bearbeitet 21.11.2024 08:38:01
- Quelle product-security@silabs.com
- CVE-Watchlists
- Unerledigt
The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellersilabs
≫
Produkt
z-wave_software_development_kit
Default Statusaffected
Version <
7.17.5
Version
0
Status
unaffected
Version <
7.18.8
Version
7.18.0
Status
unaffected
Version <
7.19.3
Version
7.19.0
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.191 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| product-security@silabs.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.