« Volver al listado

CVE-2023-41094

Estado: ModificadaCrítica (9.8)—

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration

This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-41094",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-41094",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-19T19:10:01.864508Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@silabs.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@silabs.com",
      "affectedData": [
        {
          "repo": "https://github.com/SiliconLabs/gecko_sdk",
          "vendor": "Silicon Labs",
          "modules": [
            "TouchLink"
          ],
          "product": "Ember ZNet",
          "versions": [
            {
              "status": "affected",
              "version": "7.1.3",
              "versionType": "7.1.x",
              "lessThanOrEqual": "7.1.5"
            },
            {
              "status": "affected",
              "version": "7.2.0",
              "versionType": "7.2.x",
              "lessThanOrEqual": "7.2.3"
            },
            {
              "status": "unaffected",
              "version": "7.3.0"
            }
          ],
          "platforms": [
            "32 bit",
            "ARM"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-04T21:15:09.963",
  "references": [
    {
      "url": "https://community.silabs.com/0688Y00000aIPzL",
      "tags": [
        "Permissions Required"
      ],
      "source": "product-security@silabs.com"
    },
    {
      "url": "https://community.silabs.com/0688Y00000aIPzL",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-security@silabs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-940"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-672"
        },
        {
          "lang": "en",
          "value": "CWE-772"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration\n\nThis issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected"
    },
    {
      "lang": "es",
      "value": "Los paquetes TouchLink procesados después del tiempo de espera o fuera del alcance debido a la operación de un recurso después de la caducidad y la falta de liberación del recurso después de la vida útil efectiva pueden permitir que se agregue un dispositivo fuera del alcance válido de TouchLink o de la duración del emparejamiento. Este problema afecta a Ember ZNet 7.1.x desde 7.1 .3 a 7.1.5; 7.2.x desde 7.2.0 hasta 7.2.3; La versión 7.3 y posteriores no se ven afectadas"
    }
  ],
  "lastModified": "2026-06-17T06:20:32.423",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:silabs:emberznet:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA8DEDFD-4DFD-4D09-A139-2184F9BB747F",
              "versionEndIncluding": "7.1.5",
              "versionStartIncluding": "7.1.3"
            },
            {
              "criteria": "cpe:2.3:a:silabs:emberznet:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86784D6A-6C2A-4F5F-8D06-5E0749775A8E",
              "versionEndIncluding": "7.2.3",
              "versionStartIncluding": "7.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@silabs.com"
}