Gecko Software Development Kit
Silabs · 31 CVEs
Micrium OS Network uC-HTTP server header parsing invalid pointer dereference vulnerability
Apr 16, 2024
Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
Feb 21, 2024
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commi…
Feb 20, 2024
Silicon Labs EFR32 Bluetooth stack denial of service when sending notifications to multiple clients
Feb 15, 2024
Zigbee Unauthenticated DoS via NWK Sequence number manipulation
Feb 5, 2024
Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflow
Feb 2, 2024
Glitch detection not active by default in Silicon Labs Secure Vault High devices
Jan 3, 2024
Unvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory region
Jan 2, 2024
Potential Timing vulnerability in CBC PKCS7 padding calculations
Dec 21, 2023
Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memory
Dec 15, 2023
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A spe…
Nov 14, 2023
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01.…
Nov 14, 2023
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.…
Nov 14, 2023
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-…
Nov 14, 2023
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.0…
Nov 14, 2023
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTT…
Nov 14, 2023
Bluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory access
Sep 29, 2023
Uninitialized variable in Gecko Bootloader can leak secure stack
Jul 28, 2023
Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data
Jun 15, 2023
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected d…
Jun 15, 2023
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited…
Jun 2, 2023
Key duplication in GSDK
May 18, 2023
Key duplication in GSDK
May 18, 2023
Key duplication in GSDK
May 18, 2023
Key duplication in GSDK
May 18, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-51391 | Micrium OS Network uC-HTTP server header parsing invalid pointer dereference vulnerability | HIGH | 0.79% | Apr 16, 2024 |
| CVE-2024-22473 | Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices | HIGH | 0.40% | Feb 21, 2024 |
| CVE-2023-45318 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network p… | CRITICAL | 1.75% | Feb 20, 2024 |
| CVE-2024-0240 | Silicon Labs EFR32 Bluetooth stack denial of service when sending notifications to multiple clients | MEDIUM | 0.36% | Feb 15, 2024 |
| CVE-2023-6874 | Zigbee Unauthenticated DoS via NWK Sequence number manipulation | HIGH | 0.35% | Feb 5, 2024 |
| CVE-2023-6387 | Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflow | HIGH | 0.61% | Feb 2, 2024 |
| CVE-2023-5138 | Glitch detection not active by default in Silicon Labs Secure Vault High devices | MEDIUM | 0.27% | Jan 3, 2024 |
| CVE-2023-4280 | Unvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory region | CRITICAL | 0.40% | Jan 2, 2024 |
| CVE-2023-41097 | Potential Timing vulnerability in CBC PKCS7 padding calculations | HIGH | 0.30% | Dec 21, 2023 |
| CVE-2023-4020 | Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memory | CRITICAL | 0.57% | Dec 15, 2023 |
| CVE-2023-24585 | An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead t… | CRITICAL | 1.21% | Nov 14, 2023 |
| CVE-2023-25181 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network pack… | CRITICAL | 1.69% | Nov 14, 2023 |
| CVE-2023-28391 | A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets… | CRITICAL | 1.47% | Nov 14, 2023 |
| CVE-2023-27882 | A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted netwo… | CRITICAL | 1.78% | Nov 14, 2023 |
| CVE-2023-28379 | A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet… | CRITICAL | 1.67% | Nov 14, 2023 |
| CVE-2023-31247 | A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network… | CRITICAL | 1.67% | Nov 14, 2023 |
| CVE-2023-3024 | Bluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory access | MEDIUM | 0.29% | Sep 29, 2023 |
| CVE-2023-3488 | Uninitialized variable in Gecko Bootloader can leak secure stack | MEDIUM | 0.26% | Jul 28, 2023 |
| CVE-2023-2747 | Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data | MEDIUM | 0.16% | Jun 15, 2023 |
| CVE-2023-2686 | Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack. | CRITICAL | 0.76% | Jun 15, 2023 |
| CVE-2023-2687 | Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap. | LOW | 0.25% | Jun 2, 2023 |
| CVE-2023-32100 | Key duplication in GSDK | HIGH | 0.48% | May 18, 2023 |
| CVE-2023-32099 | Key duplication in GSDK | HIGH | 0.53% | May 18, 2023 |
| CVE-2023-32098 | Key duplication in GSDK | HIGH | 0.53% | May 18, 2023 |
| CVE-2023-32097 | Key duplication in GSDK | HIGH | 0.48% | May 18, 2023 |
Showing 1 to 25 of 31 CVEs