CVE-2023-0970: Serial API Buffer Overflow in Z/IP Gateway
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0970?
CVE-2023-0970 is a vulnerability in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier that allows an attacker with physical access to overwrite global memory and potentially execute arbitrary code.
How severe is CVE-2023-0970?
CVE-2023-0970 has a severity score of 6.8, which is considered high.
What is the affected software version of CVE-2023-0970?
The affected software version of CVE-2023-0970 is SiLabs Z/IP Gateway SDK version 7.18.01 and earlier.
How can an attacker exploit CVE-2023-0970?
An attacker with invasive physical access to a Z-Wave controller device can exploit CVE-2023-0970 to overwrite global memory and potentially execute arbitrary code.
Is there a fix for CVE-2023-0970?
There is no fix available yet for CVE-2023-0970. It is recommended to follow the vendor's security advisory for updates.