« Volver al listado

CVE-2024-10106

Estado: AplazadaBaja (3.7)—

A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-10106",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-10106",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-09T15:25:55.951819Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@silabs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@silabs.com",
      "affectedData": [
        {
          "vendor": "silabs.com",
          "product": "Ember ZNet SDK",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.0.2"
            },
            {
              "status": "affected",
              "version": "7.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "7.4.4"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.6"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-01-09T15:15:12.770",
  "references": [
    {
      "url": "https://community.silabs.com/069Vm00000I1JawIAF",
      "source": "product-security@silabs.com"
    },
    {
      "url": "https://github.com/SiliconLabs/simplicity_sdk/releases",
      "source": "product-security@silabs.com"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento de búfer en el complemento de entrega de paquetes permite a un atacante sobrescribir la memoria fuera del búfer del complemento."
    }
  ],
  "lastModified": "2026-06-17T06:54:55.553",
  "sourceIdentifier": "product-security@silabs.com"
}