« Volver al listado

Silabs

Silabs Emberznet: vulnerabilidades y CVE

Silabs Emberznet tiene 17 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses11
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-4526Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the…
CVE-2026-47154Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already…
CVE-2026-47153Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices…
CVE-2026-47152Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices…
CVE-2026-47151Alta (7.1)0.38%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a…
CVE-2026-47150Alta (7.1)0.38%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come…
CVE-2026-47149Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the…
CVE-2026-47148Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already…
CVE-2026-47147Alta (7.1)0.40%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is…
CVE-2026-47146Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the…
CVE-2026-47145Alta (7.1)0.44%—25 jun 2026
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the…
CVE-2023-51394Alta (7.5)0.52%—23 feb 2024
High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.
CVE-2023-51393Alta (7.5)0.52%—23 feb 2024
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may…
CVE-2023-51392Crítica (9.8)0.24%—23 feb 2024
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
CVE-2023-41094Crítica (9.8)0.57%—4 oct 2023
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid…
CVE-2022-24938Alta (7.5)0.75%—14 nov 2022
A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
CVE-2022-24937Crítica (9.8)0.69%—14 nov 2022
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services11
  2. T1499.004 Application or System Exploitation6
  3. T1499 Endpoint Denial of Service3
  4. T1005 Data from Local System1
  5. T1565 Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Silabs