Silabs
Silabs Emberznet: vulnerabilidades y CVE
Silabs Emberznet tiene 17 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses11
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4526 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the… |
| CVE-2026-47154 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already… |
| CVE-2026-47153 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices… |
| CVE-2026-47152 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices… |
| CVE-2026-47151 | Alta (7.1) | 0.38% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a… |
| CVE-2026-47150 | Alta (7.1) | 0.38% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come… |
| CVE-2026-47149 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the… |
| CVE-2026-47148 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already… |
| CVE-2026-47147 | Alta (7.1) | 0.40% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is… |
| CVE-2026-47146 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the… |
| CVE-2026-47145 | Alta (7.1) | 0.44% | — | 25 jun 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the… |
| CVE-2023-51394 | Alta (7.5) | 0.52% | — | 23 feb 2024 | High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash. |
| CVE-2023-51393 | Alta (7.5) | 0.52% | — | 23 feb 2024 | Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may… |
| CVE-2023-51392 | Crítica (9.8) | 0.24% | — | 23 feb 2024 | Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks. |
| CVE-2023-41094 | Crítica (9.8) | 0.57% | — | 4 oct 2023 | TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid… |
| CVE-2022-24938 | Alta (7.5) | 0.75% | — | 14 nov 2022 | A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error. |
| CVE-2022-24937 | Crítica (9.8) | 0.69% | — | 14 nov 2022 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.