vciy

CVEs we hold for Silicon

Records whose assigning authority named Silicon as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-6924Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt pathSilicon Labs Matter Github
CVE-2026-6432Improper bounds validation in EmberZNet SDKSilicon Labs SiSDK
CVE-2026-5706Buffer overflow in Bluetooth Mesh SDK when handling extended advertisementsSilicon Labs BT Mesh SDK
CVE-2026-47154Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47153Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47152Level Control Move divide-by-zero in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47151Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47150IAS Zone enroll invalid table index and write in EmberZNet 9.0.2Silicon Labs EmberZNet
CVE-2026-47149Door Lock GetUserType invalid table index in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47148Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47147OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47146Color Control color-temperature assertion abort in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-47145Color Control hue/saturation assertion abort in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-4526Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2Silicon Labs EmberZNet
CVE-2026-3290Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable valuesSilicon Labs RS9116 SDK
CVE-2026-2815Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keysSilicon Labs SiSDK
CVE-2026-17610RAIL 802.15.4 Mux missing ACK can lead to DoSSilicon Labs SiSDK
CVE-2026-15419CP210x Driver Memory Corruption results in Arbitrary Code ExecutionSilicon Labs silabser.sys driver
CVE-2026-15418CP210x Memory LeakageSilicon Labs silabser.sys driver
CVE-2026-15417CP210x Denial of ServiceSilicon Labs silabser.sys driver
CVE-2025-2838Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service VulnerabilitySilicon Labs Gecko OS
CVE-2025-2837Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution VulnerabilitySilicon Labs Gecko OS
CVE-2024-9055DPA Countermeasures need reseedingSilicon Labs Simplicity SDK
CVE-2024-24731Silicon Labs Gecko OS http_download Stack-based Buffer OverflowSilicon Labs Gecko OS
CVE-2024-23973Silicon Labs Gecko OS HTTP GET Request Handling Stack-based Buffer OverflowSilicon Labs Gecko OS
CVE-2024-23938Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution VulnerabilitySilicon Labs Gecko OS
CVE-2024-23937Silicon Labs Gecko OS Debug Interface Format StringSilicon Labs Gecko OS
CVE-2024-22472Long S0 frames received by 500 series Z-Wave devices may cause buffer overflowSilicon Labs Z-Wave SDK
CVE-2024-12975Silicon Labs CPC can leak information in full duplex SPISilicon Labs Simplicity SDK
CVE-2023-51395Z-Wave S0 Decryption Vulnerability in End DevicesSilicon Labs Z-Wave SDK
CVE-2023-45318no title heldSilicon Labs Gecko Platform; Weston Embedded uC-HTTP
CVE-2023-41094Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNetSilicon Labs Ember ZNet
CVE-2023-41093Loss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuseSilicon Labs Simplicity SDK
CVE-2023-4041Second Stage Gecko Bootloader GBL Parser Buffer Overrun VulnerabilitySilicon Labs Gecko Bootloader
CVE-2023-39541no title heldSilicon Labs Gecko Platform; Weston Embedded uC-TCP-IP
CVE-2023-39540no title heldSilicon Labs Gecko Platform; Weston Embedded uC-TCP-IP
CVE-2023-31247no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-3110Buffer overflow in S0 Decryption on Unify GatewaySilicon Labs Unify Gateway
CVE-2023-28391no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-28379no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-27882no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-25181no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-24585no title heldSilicon Labs Gecko Platform; Weston Embedded Cesium NET…
CVE-2023-0972Buffer overflow in S0 Decryption on Z/IP GatweaySilicon Labs Z/IP Gateway
CVE-2023-0971Command Authentication Bypass in Z/IP GatewaySilicon Labs Z/IP Gateway
CVE-2023-0970Serial API Buffer Overflow in Z/IP GatewaySilicon Labs Z/IP Gateway
CVE-2023-0969Global read overflow in Z/IP GatewaySilicon Labs Z/IP Gateway
CVE-2022-24937Malformed Zigbee packet causes Assert in EmberZNet 7.0.0 or earlierSilicon Labs Ember ZNet
CVE-2020-10137no title heldSilicon Labs UZB-7
CVE-2018-25029no title heldSilicon Labs Z-Wave
CVE-2013-20003no title heldSilicon Labs Z-Wave; Sierra Designs Z-Wave

51 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.