CVE-2023-0971: Command Authentication Bypass in Z/IP Gateway
Published Jun 21, 2023
·Updated
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
Affected Software
1 affected component
Silabs Z\/ip Gateway Sdk<=7.18.01
Event History
Jun 21, 2023
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0971?
The severity of CVE-2023-0971 is critical with a CVSS score of 8.8.
2
How does CVE-2023-0971 allow authentication to be bypassed?
CVE-2023-0971 exploits a logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier, which allows authentication to be bypassed.
3
What can an attacker do with CVE-2023-0971?
An attacker exploiting CVE-2023-0971 can remotely administer Z-Wave controllers and recover S0/S2 encryption keys.
4
What is the affected software for CVE-2023-0971?
The affected software for CVE-2023-0971 is SiLabs Z/IP Gateway SDK versions up to and including 7.18.02.
5
How can I fix CVE-2023-0971?
To fix CVE-2023-0971, it is recommended to update to SiLabs Z/IP Gateway SDK version 7.18.03 or later.