Vulnerabilities in Silicon Labs

56 results
Vexday analysis

O portfólio de vulnerabilidades da Silicon Labs soma 50 CVEs catalogadas, das quais 11 são classificadas como críticas, e 14 surgiram nos últimos 90 dias — indicando um ritmo recente de descobertas que merece acompanhamento contínuo. A taxa de exploração ativa é de 0,0%, abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública está disponível, o que reduz o risco imediato de exploração em larga escala. A falha mais prevalente é do tipo CWE-125 (leitura fora dos limites de buffer), padrão frequentemente associado a dispositivos embarcados e firmware, segmento central dos produtos da empresa. A CVE mais perigosa em evidência atualmente é CVE-2023-27882, com escore EPSS de 0,0178, sugerindo probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o peso da criticidade geral do portfólio.

CVE-2025-2837HIGHSilicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-24731HIGHSilicon Labs Gecko OS http_download Stack-based Buffer OverflowEPSS 0.5%CVE-2026-6924HIGHWeak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt pathEPSS 0.4%CVE-2026-4526HIGHGlobal ZCL command parser missing minimum-length validation in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47149HIGHDoor Lock GetUserType invalid table index in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47145HIGHColor Control hue/saturation assertion abort in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47146HIGHColor Control color-temperature assertion abort in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47153HIGHLevel Control Step With On/Off divide-by-zero in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47152HIGHLevel Control Move divide-by-zero in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47154HIGHSimple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47148HIGHGroups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2EPSS 0.4%CVE-2023-3110CRITICALBuffer overflow in S0 Decryption on Unify GatewayEPSS 0.4%CVE-2020-9057—Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range toEPSS 0.4%CVE-2026-47147HIGHOTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2EPSS 0.4%CVE-2023-4041CRITICALSecond Stage Gecko Bootloader GBL Parser Buffer Overrun VulnerabilityEPSS 0.4%CVE-2026-6432MEDIUMImproper bounds validation in EmberZNet SDKEPSS 0.4%CVE-2026-5706HIGHBuffer overflow in Bluetooth Mesh SDK when handling extended advertisementsEPSS 0.4%CVE-2023-0972CRITICALBuffer overflow in S0 Decryption on Z/IP GatweayEPSS 0.4%CVE-2026-47151HIGHDoor Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2EPSS 0.4%CVE-2026-47150HIGHIAS Zone enroll invalid table index and write in EmberZNet 9.0.2EPSS 0.4%