VendorsSilabsgecko_software_development_kitall versions
Vulnerabilities

Silabs Silicon Labs Gecko Software Development Kit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2023-45318
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2024-02-20 · Modified
10.0EPSS 0.017
CVE-2023-27882
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.018
CVE-2023-25181
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.017
CVE-2023-31247
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.017
CVE-2023-28379
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.017
CVE-2023-28391
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.015
CVE-2023-24585
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Published 2023-11-14 · Modified
9.8EPSS 0.012
CVE-2023-2686
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
Published 2023-06-15 · Modified
9.8EPSS 0.008
CVE-2023-4280
Unvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory region
Published 2024-01-02 · Modified
9.8EPSS 0.004
CVE-2023-4020
Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memory
Published 2023-12-15 · Modified
9.1EPSS 0.006
CVE-2023-6387
Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflow
Published 2024-02-02 · Modified
7.5EPSS 0.006
CVE-2023-32098
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-32099
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-1132
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-2481
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-32100
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-0965
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-32097
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2023-32096
Key duplication in GSDK
Published 2023-05-18 · Modified
7.5EPSS 0.005
CVE-2024-22473
Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
Published 2024-02-21 · Analyzed
7.5EPSS 0.004
CVE-2023-6874
Zigbee Unauthenticated DoS via NWK Sequence number manipulation
Published 2024-02-05 · Modified
7.5EPSS 0.004
CVE-2023-41097
Potential Timing vulnerability in CBC PKCS7 padding calculations
Published 2023-12-21 · Modified
7.5EPSS 0.003
CVE-2023-5138
Glitch detection not active by default in Silicon Labs Secure Vault High devices
Published 2024-01-03 · Modified
6.8EPSS 0.003
CVE-2024-0240
Silicon Labs EFR32 Bluetooth stack denial of service when sending notifications to multiple clients
Published 2024-02-15 · Analyzed
6.5EPSS 0.004
CVE-2022-24939
Malformed Zigbee packet with invalid destination address causes Assert
Published 2022-11-17 · Modified
6.5EPSS 0.003
CVE-2023-0775
Bluetooth LE Invalid prepare write request command leads to denial of service
Published 2023-03-28 · Modified
6.5EPSS 0.003
CVE-2023-3024
Bluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory access
Published 2023-09-29 · Modified
6.5EPSS 0.003
CVE-2023-3488
Uninitialized variable in Gecko Bootloader can leak secure stack
Published 2023-07-28 · Modified
5.5EPSS 0.003
CVE-2023-2747
Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data
Published 2023-06-15 · Modified
5.5EPSS 0.002
CVE-2023-2687
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.
Published 2023-06-02 · Modified
3.3EPSS 0.002