Vulnerabilities > Silabs

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2021-27411 Integer Overflow or Wraparound vulnerability in Silabs Micrium OS 5.10.0/5.10.1/5.9.0
Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate.
network
low complexity
silabs CWE-190
6.5
2022-02-04 CVE-2013-20003 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Silabs products
Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.
high complexity
silabs CWE-338
8.3
2022-02-04 CVE-2018-25029 Unspecified vulnerability in Silabs products
The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.
low complexity
silabs
8.1
2022-01-10 CVE-2020-10137 Insufficient Verification of Data Authenticity vulnerability in Silabs 700 Series Firmware and Uzb-7
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.
low complexity
silabs CWE-345
6.5
2022-01-10 CVE-2020-9057 Missing Encryption of Sensitive Data vulnerability in multiple products
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device.
low complexity
linear silabs CWE-311
8.8
2022-01-10 CVE-2020-9058 Missing Encryption of Sensitive Data vulnerability in multiple products
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.
low complexity
silabs jasco dome linear CWE-311
8.1
2022-01-10 CVE-2020-9059 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion.
low complexity
silabs schlage CWE-770
6.5
2022-01-10 CVE-2020-9060 Resource Exhaustion vulnerability in multiple products
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.
low complexity
silabs aeotec zooz fibaro CWE-400
6.5
2022-01-10 CVE-2020-9061 Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.
low complexity
aeotec samsung zooz silabs
6.5
2021-09-07 CVE-2021-31609 Unspecified vulnerability in Silabs Iwrap 5.8/6.3.0
The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing attackers in radio range to trigger a crash in WT32i via a crafted LMP packet.
low complexity
silabs
6.5