Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0971


A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.


Published

2023-06-21T20:15:09.943

Last Modified

2024-11-21T07:38:12.630

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-268
    CWE-863
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silabs z\/ip_gateway_sdk ≤ 7.18.01 Yes

References