Vulnerabilities (CVE)

Filtered by vendor Silabs Subscribe
Filtered by product Emberznet
Total 17 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-47151 1 Silabs 1 Emberznet 2026-06-25 N/A 7.1 HIGH
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.
CVE-2026-47150 1 Silabs 1 Emberznet 2026-06-25 N/A 7.1 HIGH
In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.
CVE-2026-47149 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.
CVE-2026-47148 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Groups cluster may be impacted.
CVE-2026-47147 1 Silabs 1 Emberznet 2026-06-25 N/A 7.1 HIGH
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.
CVE-2026-47146 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
CVE-2026-47145 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
CVE-2026-47152 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
CVE-2026-47153 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
CVE-2026-47154 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.
CVE-2026-4526 1 Silabs 1 Emberznet 2026-06-25 N/A 6.5 MEDIUM
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.
CVE-2023-51394 1 Silabs 1 Emberznet 2026-06-17 N/A 5.3 MEDIUM
High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.
CVE-2023-51393 1 Silabs 1 Emberznet 2026-06-17 N/A 5.3 MEDIUM
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.
CVE-2023-51392 1 Silabs 1 Emberznet 2026-06-17 N/A 6.2 MEDIUM
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
CVE-2023-41094 1 Silabs 1 Emberznet 2026-06-17 N/A 10.0 CRITICAL
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected
CVE-2022-24938 1 Silabs 1 Emberznet 2026-06-17 N/A 6.5 MEDIUM
A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
CVE-2022-24937 1 Silabs 1 Emberznet 2026-06-17 N/A 6.5 MEDIUM
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.