CVE-2022-24939: Malformed Zigbee packet with invalid destination address causes Assert
Published Nov 17, 2022
·Updated
A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
Affected Software
2 affected components
Silabs Gecko Software Development Kit
Silabs Zigbee Emberznet
Event History
Nov 17, 2022
CVE Published
via MITRE·11:35 PM
Data Sourced
via MITRE·11:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-24939.
2
What is the severity of CVE-2022-24939?
The severity of CVE-2022-24939 is medium.
3
Which software is affected by CVE-2022-24939?
The Silabs Gecko Software Development Kit and Silabs Zigbee Emberznet are affected by CVE-2022-24939.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-24939?
The CWE for CVE-2022-24939 is CWE-787 and CWE-119.
5
How can I fix CVE-2022-24939?
There is no specific fix mentioned for CVE-2022-24939. It is recommended to follow the guidance provided by Silabs and keep the affected software up to date.