CVE-2023-2686: Buffer Overflow
Published Jun 15, 2023
·Updated
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
Affected Software
1 affected component
Silabs Gecko Software Development Kit<=4.2.3
Event History
Jun 15, 2023
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-2686?
CVE-2023-2686 is a buffer overflow vulnerability in the Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier.
2
How severe is CVE-2023-2686?
CVE-2023-2686 has a severity rating of critical with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2023-2686?
Silicon Labs Gecko SDK versions up to and including 4.2.3 are affected by CVE-2023-2686.
4
How can a connected device exploit CVE-2023-2686?
A connected device can exploit CVE-2023-2686 by writing a payload onto the stack.
5
Is there a fix available for CVE-2023-2686?
Yes, updating to a version later than 4.2.3 of Silicon Labs Gecko SDK fixes the CVE-2023-2686 vulnerability.