CVE-2023-51393: Potential DoS due to BusFault and Assert in Ember ZNet legacy packet buffer
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51393?
CVE-2023-51393 has a medium severity due to the potential for an uncontrolled resource consumption vulnerability that can crash the device.
How do I fix CVE-2023-51393?
To fix CVE-2023-51393, upgrade to Silicon Labs Ember ZNet SDK version 7.4.0.0 or later, or Silicon Labs Gecko SDK version 4.4.0 or later.
What systems are affected by CVE-2023-51393?
CVE-2023-51393 affects Silicon Labs Ember ZNet SDK versions prior to 7.4.0.0 and Gecko SDK versions prior to 4.4.0.
What kind of attack can be executed using CVE-2023-51393?
An attacker can exploit CVE-2023-51393 to trigger a bus fault and crash the device due to resource allocation without limits.
Is CVE-2023-51393 related to denial of service attacks?
Yes, CVE-2023-51393 can lead to denial of service conditions by causing the affected devices to crash.