Show filters
98 Total Results
Displaying 21-30 of 98
Sort by:
Attacker Value
Unknown

CVE-2024-6657

Disclosure Date: October 11, 2024 (last updated October 30, 2024)
A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset is required to recover the peripheral device.
0
Attacker Value
Unknown

CVE-2024-23938

Disclosure Date: September 28, 2024 (last updated October 04, 2024)
Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23184
Attacker Value
Unknown

CVE-2024-2502

Disclosure Date: August 29, 2024 (last updated August 30, 2024)
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper reset) occurs. This impacts Series 2 HSE-SVH devices, including xG23B, xG24B, xG25B, and xG28B, but does not impact xG21B. To mitigate this issue, upgrade to SE Firmware version 2.2.6 or later.
0
Attacker Value
Unknown

CVE-2023-41093

Disclosure Date: July 12, 2024 (last updated September 11, 2024)
Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.
Attacker Value
Unknown

CVE-2024-3043

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.
0
Attacker Value
Unknown

CVE-2024-3017

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.
0
Attacker Value
Unknown

CVE-2024-4013

Disclosure Date: June 06, 2024 (last updated June 07, 2024)
A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioning scheme was changed from Gecko SDK vX.Y.Z to Simplicity SDK YYYY.MM.Patch#.
0
Attacker Value
Unknown

CVE-2024-3052

Disclosure Date: April 26, 2024 (last updated September 27, 2024)
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.
0
Attacker Value
Unknown

CVE-2024-3051

Disclosure Date: April 26, 2024 (last updated September 27, 2024)
Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time.
0
Attacker Value
Unknown

CVE-2023-51394

Disclosure Date: February 23, 2024 (last updated February 13, 2025)
High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.