CVE-2025-1394
- EPSS 0.04%
- Veröffentlicht 30.07.2025 08:15:33
- Zuletzt bearbeitet 31.07.2025 18:42:37
Failure to handle the error status returned by the buffer management APIs in SiLabs EmberZNet Zigbee stack may result in data leaks or potential Denial of Service (DoS).
CVE-2025-1221
- EPSS 0.03%
- Veröffentlicht 30.07.2025 08:15:33
- Zuletzt bearbeitet 31.07.2025 18:42:37
A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host system (CPCd) due to heavy Zigbee traffic, resulting in a Denial of Service (DoS) attack, Only hard reset will bring the device t...
CVE-2024-3052
- EPSS 0.14%
- Veröffentlicht 26.04.2024 22:15:08
- Zuletzt bearbeitet 27.08.2025 22:15:40
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.
CVE-2023-51391
- EPSS 0.24%
- Veröffentlicht 16.04.2024 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:38:00
A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially allowing a device crash and Denial of Service.
CVE-2024-22473
- EPSS 0.07%
- Veröffentlicht 21.02.2024 19:15:08
- Zuletzt bearbeitet 12.02.2025 16:52:42
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
CVE-2023-45318
- EPSS 0.61%
- Veröffentlicht 20.02.2024 15:15:08
- Zuletzt bearbeitet 12.02.2025 18:50:45
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trig...
CVE-2024-0240
- EPSS 0.03%
- Veröffentlicht 15.02.2024 21:15:08
- Zuletzt bearbeitet 05.02.2025 22:37:50
A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.
CVE-2023-6874
- EPSS 0.06%
- Veröffentlicht 05.02.2024 18:15:51
- Zuletzt bearbeitet 21.11.2024 08:44:44
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
CVE-2023-6387
- EPSS 3.2%
- Veröffentlicht 02.02.2024 16:15:53
- Zuletzt bearbeitet 21.11.2024 08:43:45
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
CVE-2023-5138
- EPSS 0.05%
- Veröffentlicht 03.01.2024 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:41:08
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.