Vulnerabilities > Silabs > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-04 | CVE-2013-20003 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Silabs products Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic. | 8.3 |
2022-02-04 | CVE-2018-25029 | Unspecified vulnerability in Silabs products The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic. low complexity silabs | 8.1 |
2022-01-10 | CVE-2020-9057 | Missing Encryption of Sensitive Data vulnerability in multiple products Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. | 8.8 |
2022-01-10 | CVE-2020-9058 | Missing Encryption of Sensitive Data vulnerability in multiple products Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection. | 8.1 |
2021-01-26 | CVE-2020-13582 | NULL Pointer Dereference vulnerability in Silabs Micrium Uc-Http 3.01.00 A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. | 7.5 |
2020-08-20 | CVE-2020-15531 | Classic Buffer Overflow vulnerability in Silabs Bluetooth LOW Energy Software Development KIT 2.13.0.0/2.13.1.0/2.13.2.0 Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. | 8.8 |