CVE-2023-0972: Buffer overflow in S0 Decryption on Z/IP Gatweay
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0972?
CVE-2023-0972 is a vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier that allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
How severe is CVE-2023-0972?
CVE-2023-0972 is classified as critical with a severity score of 8.8.
What software versions are affected by CVE-2023-0972?
SiLabs Z/IP Gateway 7.18.01 and earlier versions are affected by CVE-2023-0972.
How can an attacker exploit CVE-2023-0972?
An unauthenticated attacker within Z-Wave range can exploit CVE-2023-0972 by overflowing a stack buffer to execute arbitrary code.
Is there a fix available for CVE-2023-0972?
The vendor has not provided information on a fix for CVE-2023-0972. It is recommended to contact the vendor for further assistance.