CVE-2023-0969: Global read overflow in Z/IP Gateway
Published Jun 21, 2023
·Updated
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.
Affected Software
1 affected component
Silabs Z\/ip Gateway Sdk<=7.18.01
Event History
Jun 21, 2023
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0969?
The severity of CVE-2023-0969 is low with a severity value of 3.5.
2
How does CVE-2023-0969 affect SiLabs Z/IP Gateway?
CVE-2023-0969 affects SiLabs Z/IP Gateway versions up to and including 7.18.01.
3
What is the vulnerability type for CVE-2023-0969?
The vulnerability type for CVE-2023-0969 is CWE-119 and CWE-125.
4
Can an attacker exploit CVE-2023-0969 remotely?
No, CVE-2023-0969 requires an authenticated attacker within Z-Wave range to exploit the vulnerability.
5
Is there a fix available for CVE-2023-0969?
The vendor has released an updated version of the SiLabs Z/IP Gateway SDK to address the vulnerability. Please refer to the vendor's advisories for more information.