« Volver al listado

CVE-2023-51395

Estado: AplazadaAlta (8.8)—

The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-51395",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-51395",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-27T16:36:30.844451Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@silabs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@silabs.com",
      "affectedData": [
        {
          "repo": "https://github.com/SiliconLabs/gecko_sdk/releases",
          "vendor": "Silicon Labs",
          "product": "Z-Wave SDK",
          "versions": [
            {
              "status": "unaffected",
              "version": "7.20.0"
            },
            {
              "status": "unaffected",
              "version": "7.19.3"
            },
            {
              "status": "unaffected",
              "version": "7.18.8"
            },
            {
              "status": "unaffected",
              "version": "7.17.5"
            }
          ],
          "platforms": [
            "ARM",
            "32 bit"
          ],
          "packageName": "Z-Wave SDK",
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:h:silabs:z-wave_software_development_kit:*:*:*:*:*:*:*:*"
          ],
          "vendor": "silabs",
          "product": "z-wave_software_development_kit",
          "versions": [
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.17.5",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.18.0",
              "lessThan": "7.18.8",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.19.0",
              "lessThan": "7.19.3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-03-07T05:15:53.373",
  "references": [
    {
      "url": "https://community.silabs.com/068Vm0000029Xq5",
      "source": "product-security@silabs.com"
    },
    {
      "url": "https://community.silabs.com/068Vm0000029Xq5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-security@silabs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        },
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad descrita por CVE-2023-0972 también se descubrió en los dispositivos finales Z-Wave de Silicon Labs. Esta vulnerabilidad puede permitir que un atacante no autenticado dentro del alcance de Z-Wave desbordamiento de búfer en la región stack de la memoria, lo que lleva a la ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T06:40:52.410",
  "sourceIdentifier": "product-security@silabs.com"
}