First published: Wed Jun 21 2023(Updated: )
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.
Credit: product-security@silabs.com product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Z\/ip Gateway Sdk | <=7.18.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0970 is a vulnerability in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier that allows an attacker with physical access to overwrite global memory and potentially execute arbitrary code.
CVE-2023-0970 has a severity score of 6.8, which is considered high.
The affected software version of CVE-2023-0970 is SiLabs Z/IP Gateway SDK version 7.18.01 and earlier.
An attacker with invasive physical access to a Z-Wave controller device can exploit CVE-2023-0970 to overwrite global memory and potentially execute arbitrary code.
There is no fix available yet for CVE-2023-0970. It is recommended to follow the vendor's security advisory for updates.