Vulnerabilities
Vulnerable Software
Silabs:  >> Z/ip Gateway Sdk  Security Vulnerabilities
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.
CVSS Score
6.4
EPSS Score
0.002
Published
2023-12-14
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
CVSS Score
9.6
EPSS Score
0.0
Published
2023-06-21
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.
CVSS Score
3.5
EPSS Score
0.0
Published
2023-06-21
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.
CVSS Score
7.1
EPSS Score
0.0
Published
2023-06-21
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
CVSS Score
9.6
EPSS Score
0.0
Published
2023-06-21


Contact Us

Shodan ® - All rights reserved