Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Gecko_software_development_kit
(Silabs)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 30 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2024-02-20 | CVE-2023-45318 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability. | Gecko_software_development_kit, Uc\-Http | 9.8 | ||
2024-02-21 | CVE-2024-22473 | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. | Gecko_software_development_kit | 7.5 | ||
2024-02-15 | CVE-2024-0240 | A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop. | Gecko_software_development_kit | 6.5 | ||
2022-11-18 | CVE-2022-24939 | A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error. | Gecko_software_development_kit, Zigbee_emberznet | 6.5 | ||
2023-03-28 | CVE-2023-0775 | An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service. | Gecko_software_development_kit | 6.5 | ||
2023-05-18 | CVE-2023-0965 | Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM. | Gecko_software_development_kit | 7.5 | ||
2023-05-18 | CVE-2023-1132 | Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM. | Gecko_software_development_kit | 7.5 | ||
2023-05-18 | CVE-2023-2481 | Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM. | Gecko_software_development_kit | 7.5 | ||
2023-05-18 | CVE-2023-32096 | Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM. | Gecko_software_development_kit | 7.5 | ||
2023-05-18 | CVE-2023-32097 | Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM. | Gecko_software_development_kit | 7.5 |