« Back to list

CVE-2024-3017

Status: DeferredMedium (6.5)—

In a

Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-3017",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-3017",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-03T19:31:21.582199Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "product-security@silabs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@silabs.com",
      "affectedData": [
        {
          "vendor": "silabs.com",
          "product": "SiSDK",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2024.06.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:silabs:sisdk:*:*:*:*:*:*:*:*"
          ],
          "vendor": "silabs",
          "product": "sisdk",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2024.06.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-06-27T19:15:14.483",
  "references": [
    {
      "url": "https://community.silabs.com/069Vm000007UEhZIAW",
      "source": "product-security@silabs.com"
    },
    {
      "url": "https://github.com/SiliconLabs/simplicity_sdk",
      "source": "product-security@silabs.com"
    },
    {
      "url": "https://community.silabs.com/069Vm000007UEhZIAW",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/SiliconLabs/simplicity_sdk",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "product-security@silabs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In a \n\nSilicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service."
    },
    {
      "lang": "es",
      "value": "En una puerta de enlace multiprotocolo de Silicon Labs, un puntero corrupto a datos almacenados en un búfer en un coprocesador de radio multiprotocolo (RCP) hace que la tarea de la aplicación OpenThread Border Router (OTBR) que se ejecuta en la plataforma host falle, lo que permite que un atacante cause una denegación temporal de servicio."
    }
  ],
  "lastModified": "2026-06-17T07:43:08.447",
  "sourceIdentifier": "product-security@silabs.com"
}