First published: Thu Dec 14 2023(Updated: )
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Z/IP Gateway SDK | <=7.18.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4489 is classified as high severity due to the potential for unauthorized access through predictable encryption key generation.
To fix CVE-2023-4489, upgrade to Z/IP Gateway SDK version 7.18.4 or later, which addresses the uninitialized PRNG issue.
CVE-2023-4489 affects Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK versions up to and including 7.18.3.
The risk associated with CVE-2023-4489 includes potential unauthorized access to network keys, leading to compromised networks.
Yes, a patch is available by upgrading to Z/IP Gateway SDK version 7.18.4, which resolves the vulnerability.