silabs CVE Vulnerabilities & Metrics

Focus on silabs vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About silabs Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with silabs. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total silabs CVEs: 68
Earliest CVE date: 09 Dec 2018, 19:29 UTC
Latest CVE date: 28 Sep 2024, 06:15 UTC

Latest CVE reference: CVE-2024-23938

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -95.65%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -95.65%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical silabs CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.19

Max CVSS: 8.3

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 57
4.0-6.9 9
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS silabs CVEs

These are the five CVEs with the highest CVSS scores for silabs, sorted by severity first and recency.

All CVEs for silabs

CVE-2024-23938 silabs vulnerability CVSS: 0 28 Sep 2024, 06:15 UTC

Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23184

CVE-2023-41093 silabs vulnerability CVSS: 0 12 Jul 2024, 20:15 UTC

Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

CVE-2023-51394 silabs vulnerability CVSS: 0 23 Feb 2024, 20:15 UTC

High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

CVE-2023-51393 silabs vulnerability CVSS: 0 23 Feb 2024, 20:15 UTC

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.

CVE-2023-51392 silabs vulnerability CVSS: 0 23 Feb 2024, 17:15 UTC

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

CVE-2024-22473 silabs vulnerability CVSS: 0 21 Feb 2024, 19:15 UTC

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

CVE-2023-45318 silabs vulnerability CVSS: 0 20 Feb 2024, 15:15 UTC

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2024-0240 silabs vulnerability CVSS: 0 15 Feb 2024, 21:15 UTC

A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.

CVE-2023-6874 silabs vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

CVE-2023-6387 silabs vulnerability CVSS: 0 02 Feb 2024, 16:15 UTC

A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

CVE-2023-5138 silabs vulnerability CVSS: 0 03 Jan 2024, 23:15 UTC

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

CVE-2023-4280 silabs vulnerability CVSS: 0 02 Jan 2024, 17:15 UTC

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

CVE-2023-41097 silabs vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

CVE-2023-4020 silabs vulnerability CVSS: 0 15 Dec 2023, 21:15 UTC

An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.

CVE-2023-5310 silabs vulnerability CVSS: 0 15 Dec 2023, 16:15 UTC

A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.

CVE-2023-4489 silabs vulnerability CVSS: 0 14 Dec 2023, 23:15 UTC

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

CVE-2023-31247 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-28391 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-28379 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-27882 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-25181 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-24585 silabs vulnerability CVSS: 0 14 Nov 2023, 10:15 UTC

An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

CVE-2023-41096 silabs vulnerability CVSS: 0 26 Oct 2023, 14:15 UTC

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

CVE-2023-41095 silabs vulnerability CVSS: 0 26 Oct 2023, 14:15 UTC

Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier.

CVE-2023-3487 silabs vulnerability CVSS: 0 20 Oct 2023, 15:15 UTC

An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.

CVE-2020-27630 silabs vulnerability CVSS: 0 10 Oct 2023, 17:15 UTC

In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

CVE-2023-41094 silabs vulnerability CVSS: 0 04 Oct 2023, 21:15 UTC

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected

CVE-2023-3024 silabs vulnerability CVSS: 0 29 Sep 2023, 17:15 UTC

Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

CVE-2023-4041 silabs vulnerability CVSS: 0 23 Aug 2023, 05:15 UTC

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This issue affects "Standalone" and "Application" versions of Gecko Bootloader.

CVE-2023-3488 silabs vulnerability CVSS: 0 28 Jul 2023, 16:15 UTC

Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

CVE-2023-3110 silabs vulnerability CVSS: 0 21 Jun 2023, 20:15 UTC

Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

CVE-2023-0972 silabs vulnerability CVSS: 0 21 Jun 2023, 20:15 UTC

Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

CVE-2023-0971 silabs vulnerability CVSS: 0 21 Jun 2023, 20:15 UTC

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

CVE-2023-0970 silabs vulnerability CVSS: 0 21 Jun 2023, 20:15 UTC

Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.

CVE-2023-0969 silabs vulnerability CVSS: 0 21 Jun 2023, 20:15 UTC

A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.

CVE-2023-2747 silabs vulnerability CVSS: 0 15 Jun 2023, 20:15 UTC

The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.

CVE-2023-2683 silabs vulnerability CVSS: 0 15 Jun 2023, 20:15 UTC

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

CVE-2023-2686 silabs vulnerability CVSS: 0 15 Jun 2023, 19:15 UTC

Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

CVE-2023-2687 silabs vulnerability CVSS: 0 02 Jun 2023, 16:15 UTC

Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.

CVE-2023-32100 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-32099 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-32098 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-32097 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-32096 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-2481 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-1132 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-0965 silabs vulnerability CVSS: 0 18 May 2023, 19:15 UTC

Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

CVE-2023-0775 silabs vulnerability CVSS: 0 28 Mar 2023, 17:15 UTC

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

CVE-2022-24939 silabs vulnerability CVSS: 0 18 Nov 2022, 00:15 UTC

 A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

CVE-2022-24942 silabs vulnerability CVSS: 0 15 Nov 2022, 21:15 UTC

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

CVE-2022-24938 silabs vulnerability CVSS: 0 14 Nov 2022, 18:15 UTC

A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

CVE-2022-24937 silabs vulnerability CVSS: 0 14 Nov 2022, 18:15 UTC

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

CVE-2022-24936 silabs vulnerability CVSS: 0 02 Nov 2022, 18:15 UTC

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

CVE-2022-24611 silabs vulnerability CVSS: 6.1 17 May 2022, 18:15 UTC

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.

CVE-2021-27411 silabs vulnerability CVSS: 6.4 03 May 2022, 21:15 UTC

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

CVE-2018-25029 silabs vulnerability CVSS: 4.8 04 Feb 2022, 23:15 UTC

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.

CVE-2013-20003 silabs vulnerability CVSS: 7.9 04 Feb 2022, 23:15 UTC

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.

CVE-2020-9061 silabs vulnerability CVSS: 3.3 10 Jan 2022, 14:10 UTC

Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.

CVE-2020-9060 silabs vulnerability CVSS: 6.1 10 Jan 2022, 14:10 UTC

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

CVE-2020-9059 silabs vulnerability CVSS: 6.1 10 Jan 2022, 14:10 UTC

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 version 3.42 door lock is vulnerable and fails open at a low battery level.

CVE-2020-9058 silabs vulnerability CVSS: 4.8 10 Jan 2022, 14:10 UTC

Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.

CVE-2020-9057 silabs vulnerability CVSS: 8.3 10 Jan 2022, 14:10 UTC

Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware upgrades cannot directly address this vulnerability as it is an issue with the Z-Wave specification for these legacy chipsets. One way to protect against this vulnerability is to use 500 or 700 series chipsets that support Security 2 (S2) encryption. As examples, the Linear WADWAZ-1 version 3.43 and WAPIRZ-1 version 3.43 (with 300 series chipsets) are vulnerable.

CVE-2020-10137 silabs vulnerability CVSS: 3.3 10 Jan 2022, 14:10 UTC

Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random payload, denying service by blocking the processing of upcoming events.

CVE-2021-31609 silabs vulnerability CVSS: 3.3 07 Sep 2021, 07:15 UTC

The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing attackers in radio range to trigger a crash in WT32i via a crafted LMP packet.

CVE-2020-13582 silabs vulnerability CVSS: 5.0 26 Jan 2021, 19:15 UTC

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-15532 silabs vulnerability CVSS: 3.3 20 Aug 2020, 01:17 UTC

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

CVE-2020-15531 silabs vulnerability CVSS: 5.8 20 Aug 2020, 01:17 UTC

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

CVE-2018-19983 silabs vulnerability CVSS: 6.1 09 Dec 2018, 19:29 UTC

An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided "Nonce Get (0x98 0x81)" frames. The reason for dividing the "Nonce Get" frame is that, in security version S0, when a node receives a "Nonce Get" frame, the node produces a random new nonce and sends it to the Src node of the received "Nonce Get" frame. After the nonce value is generated and transmitted, the node transitions to wait mode. At this time, when "Nonce Get" is received again, the node discards the previous nonce value and generates a random nonce again. Therefore, because the frame is encrypted with previous nonce value, the received normal frame cannot be decrypted.