CVE-2023-41094: Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration
This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-41094.
What is the title of this vulnerability?
The title of this vulnerability is TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime.
What is the severity of CVE-2023-41094?
The severity of CVE-2023-41094 is critical with a CVSS score of 9.8.
What software is affected by this vulnerability?
The affected software is Silabs Emberznet versions 7.1.3 to 7.1.5 and 7.2.0 to 7.2.3.
How can this vulnerability be fixed?
There is currently no known fix for this vulnerability. It is recommended to follow the suggestions provided by the vendor.