vciy

CVEs we hold for Silabs.com

Records whose assigning authority named Silabs.com as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8676no title heldsilabs.com Simplicity SDK
CVE-2026-65936RS9116W/SiWx917 malformed packet with increased length field causes memory leaksilabs.com WiseConnect
CVE-2026-65935Bypassing passkey entry in legacy pairingsilabs.com WiseConnect
CVE-2026-65934BT122 plaintext pause encryption request causes DOSsilabs.com BT122
CVE-2026-65933BT122 malformed packet with increased length field causes memory leaksilabs.com BT122
CVE-2026-65932BT122 stops advertisingsilabs.com BT122
CVE-2026-4930DPA Countermeasures weakening on Series 3 devicessilabs.com Simplicity SDK
CVE-2026-19293SMP security requestsilabs.com WiseConnect
CVE-2026-19292Bluetooth re-pairing with legitimate device can use lower security levelsilabs.com WiseConnect
CVE-2026-19291Bluetooth re-pairing can use a lower security level than previoussilabs.com WiseConnect
CVE-2026-16769RS9116W/SiWx917 plaintext pause encryption request causes DOSsilabs.com WiseCnnect
CVE-2026-16101forced re-pairing with already bonded devicesilabs.com WiseConnect
CVE-2026-0619Integer Wraparound DoS in Silicon Labs Matter Implementationsilabs.com Silicon Labs Matter
CVE-2025-8414Zigbee Green Power Host Buffer Overflow Vulnerabilitysilabs.com Gecko SDK
CVE-2025-7964Zigbee Router Denial of Servicesilabs.com Silicon Labs Zigbee Stack
CVE-2025-7448Man in the middle (MitM) attack vulnerability in Wi-SUN librarysilabs.com Wi-SUN Stack
CVE-2025-7432DPA countermeasures not reseeded under certain conditionssilabs.com Simplicity SDK
CVE-2025-4321DoS in RS9116W-WiSeConnect L2CAP protocol due to reception of malformed packetssilabs.com RS9116W
CVE-2025-3873Buffer overflow in Si91x crypto APIssilabs.com WiseConnect
CVE-2025-3301DPA Countermeasures Unavailable for Certain Cryptographic Operations on Series 2 Devicessilabs.com Series 2 SoCs and associated modules
CVE-2025-2329High traffic causes corrupt SPI packets in OpenThread leading to denial of servicesilabs.com OpenThread
CVE-2025-14972Insufficient DPA countermeasure reseedingsilabs.com Simplicity SDK
CVE-2025-14547ECJ-PAKE Integer Underflow Vulnerability in Silicon Labs PSA Crypto and SE Manager APIssilabs.com Gecko SDK
CVE-2025-14055Integer underflow in Secure NCP hostsilabs.com Simplicity SDK, Gecko SDK
CVE-2025-1394Denial of Service (DoS) vulnerabilitiey in Zigbee librarysilabs.com Zigbee Stack
CVE-2025-12986Denial of Service Vulnerability in Silicon Labs WF200 and WGM160P Devicessilabs.com Gecko SDK
CVE-2025-1221DoS in Zigbee device due to heavy trafficsilabs.com Zigbee
CVE-2025-12131Truncated 802.15.4 packet leads to denial of servicesilabs.com EmberZNet SDK
CVE-2025-11571Command Execution vulnerability in Simplicity Installersilabs.com Simplicity Installer tool (Silicon Labs Tool -…
CVE-2025-11004Reflected XSS vulnerability in Simplicity Device Manager toolsilabs.com Simplicity Device Manager
CVE-2025-10933Silicon Labs Z-Wave Protocol Controller Integer underflow vulnerability leads to out of bounds readsilabs.com Z-Wave Protocol Controller
CVE-2025-10693Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Securesilabs.com Silicon Labs Z-Wave SDK
CVE-2025-10285Simplcity Device Manager exposes NTLMv2 hashsilabs.com Simplicity Studio V6
CVE-2024-9499Uncontrolled search path can lead to DLL hijacking in USBXpress Win 98SE Dev Kit installersilabs.com USBXpress Win 98SE Dev Kit
CVE-2024-9498Uncontrolled search path can lead to DLL hijacking in USBXpress SDK installersilabs.com USBXpress SDK
CVE-2024-9497Uncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installersilabs.com USBXpress 4 SDK
CVE-2024-9496Uncontrolled search path can lead to DLL hijacking in USBXpress Dev Kit installersilabs.com USBXpress Dev Kit
CVE-2024-9495Uncontrolled search path can lead to DLL hijacking in CP210x VCP Windows installersilabs.com CP210x VCP Windows
CVE-2024-9494Uncontrolled search path can lead to DLL hijacking in CP210 VCP Win 2k installersilabs.com CP210 VCP Win 2k
CVE-2024-9493Uncontrolled search path can lead to DLL hijacking in ToolStick installersilabs.com ToolStick
CVE-2024-9492Uncontrolled search path can lead to DLL hijacking in Flash Programming Utility installersilabs.com Flash Programming Utility
CVE-2024-9491Uncontrolled search path can lead to DLL hijacking in Configuration Wizard 2 installersilabs.com Configuration Wizard 2
CVE-2024-9490Uncontrolled search path can lead to DLL hijacking in Silicon Labs IDE installersilabs.com Silicon Labs IDE (8-bit)
CVE-2024-8361DoS caused due to wrong hash length returned for SHA2/224 algorithmsilabs.com WiSeConnect SDK
CVE-2024-7322Dos in ZigBee device due to unsolicited encrypted rejoin responsesilabs.com EmberZNet
CVE-2024-7139Denial of Service in Silicon Labs RS9116 Bluetooth SDKsilabs.com RS9116 Bluetooth SDK
CVE-2024-7138Denial of Service in Silicon Labs RS9116 Bluetooth SDKsilabs.com RS9116 Bluetooth SDK
CVE-2024-7137Denial of Service in Silicon Labs RS9116 Bluetooth SDKsilabs.com RS9116 Bluetooth SDK
CVE-2024-6657BLE peripheral DoS after few cycles of connect/disconnectssilabs.com EFR32 BLE SDK
CVE-2024-6352Malformed packet leads to denial of service in APS layersilabs.com SiSDK
CVE-2024-6351Malformed packet leads to denial of service in NWK/APS layersilabs.com SiSDK
CVE-2024-6350EmberZNet malformed MAC layer packet leads to denial of servicesilabs.com Simplicity SDK
CVE-2024-4013Failure to update BT Mesh Replay Protection Listsilabs.com Gecko SDK
CVE-2024-3052Z/IP Gateway S2 Nonce Get Denial of Service Vulnerabilitysilabs.com Z/IP Gateway SDK
CVE-2024-3051Z/IP Gateway Device Reset Locally Denial of Service Vulnerabilitysilabs.com Z/IP Gateway SDK
CVE-2024-3043Zigbee co-ordinator realignment packet may lead to denial of servicesilabs.com Ember ZNet SDK
CVE-2024-3017Denial of service in multi-protocol gateway - Zigbee + Threadsilabs.com SiSDK
CVE-2024-2502Failure to update the tamper reset cause register when a tamper event occurssilabs.com SE Firmware
CVE-2024-22473Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devicessilabs.com GSDK
CVE-2024-10106Ember ZNet buffer overflow in 'packet handoff' pluginsilabs.com Ember ZNet SDK
CVE-2024-0240Silicon Labs EFR32 Bluetooth stack denial of service when sending notifications to multiple clientssilabs.com GSDK
CVE-2023-6874Zigbee Unauthenticated DoS via NWK Sequence number manipulationsilabs.com GSDK
CVE-2023-6640Silicon Labs PC Controller v5.54.0 and Earlier Denial of Service Vulnerabilitysilabs.com PC Controller
CVE-2023-6533Silicon Labs PC Controller Denial of Service Vulnerabilitysilabs.com PC Controller
CVE-2023-6387Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflowsilabs.com GSDK
CVE-2023-5310Z-Wave Denial of Service caused by Stream of Packetssilabs.com Gecko SDK
CVE-2023-51394Potential DoS for EFR32xxx parts in high traffic environments due to null buffer dereference / crashsilabs.com Ember ZNet SDK
CVE-2023-51393Potential DoS due to BusFault and Assert in Ember ZNet legacy packet buffersilabs.com Ember ZNet SDK
CVE-2023-51392Silicon Labs EFR32xxx parts with classic key storage do not use hardware accelerated AES-CCMsilabs.com Ember ZNet SDK
CVE-2023-51391Micrium OS Network uC-HTTP server header parsing invalid pointer dereference vulnerabilitysilabs.com
CVE-2023-5138Glitch detection not active by default in Silicon Labs Secure Vault High devicessilabs.com GSDK
CVE-2023-4489Z/IP Gateway Use of Uninitialized PRNG when Generating S0 Encryption Keysilabs.com Z/IP Gateway SDK
CVE-2023-4280Unvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory regionsilabs.com GSDK
CVE-2023-41097Potential Timing vulnerability in CBC PKCS7 padding calculationssilabs.com GSDK
CVE-2023-41096Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet devicessilabs.com Ember ZNet SDK
CVE-2023-41095Keys Stored in Plaintext on Secure Vault High for Silabs OpenThread devicessilabs.com OpenThread SDK
CVE-2023-4020Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memorysilabs.com GSDK
CVE-2023-3488Uninitialized variable in Gecko Bootloader can leak secure stacksilabs.com Gecko Bootloader
CVE-2023-3487Integer overflow in Silicon Labs Gecko Bootloader leads to unbounded memory accesssilabs.com GSDK
CVE-2023-32100Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-32099Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-32098Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-32097Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-32096Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-3024Bluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory accesssilabs.com GSDK
CVE-2023-2747Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored datasilabs.com GSDK
CVE-2023-2687no title heldsilabs.com Gecko SDK
CVE-2023-2686no title heldsilabs.com Gecko Platform
CVE-2023-2683Connection update while closing connection may lead to denial-of-servicesilabs.com Bluetooth SDK
CVE-2023-2481Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-1262Missing MAC layer security in Wi-SUN Linux Border Routersilabs.com Wi-SUN Linux Border Router
CVE-2023-1261Missing MAC layer security in Wi-SUN SDKsilabs.com Wi-SUN SDK
CVE-2023-1132Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-0965Key duplication in GSDKsilabs.com Gecko Platform
CVE-2023-0775Bluetooth LE Invalid prepare write request command leads to denial of servicesilabs.com GSDK
CVE-2022-24942Heap-based buffer overflow in MicriumOS HTTP Server allows potential remote code executionsilabs.com Gecko Platform
CVE-2022-24939Malformed Zigbee packet with invalid destination address causes Assertsilabs.com Ember ZNet
CVE-2022-24938Malformed Zigbee packet causes Assert in EmberZNet 7.0.1 or earliersilabs.com Ember ZNet
CVE-2022-24936Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devicessilabs.com Gecko Bootloader

99 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.