Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.10%—Redpine Signals Rs9116wAIRedpine Signals Siwx917AI8/9/20268/9/2026
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
Pendiente de análisisMedia (6.4)0.16%—Silabs Siwx917AIZephyrproject ZephyrAI31/8/20261/9/2026
The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack; the driver only borrows it to copy the frame bytes into a local net_buf. Before the fix, after…
Pendiente de análisisMedia (5.3)0.25%—Silabs Rs9116wAISilabs Siwx917AI13/8/20268/9/2026
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
Pendiente de análisisAlta (7.6)0.25%—Silabs Rs9116wAISilabs Siwx917AI13/8/20268/9/2026
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below.
Pendiente de análisisAlta (8.8)0.35%—Redpine Signals Rs9116wAISilabs Siwx917AI13/8/20268/9/2026
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
Pendiente de análisisAlta (8.7)0.45%—Silabs Siwx917AI23/7/20268/9/2026
A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.