First published: Fri Feb 23 2024(Updated: )
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silicon Labs Ember ZNet SDK | <7.4.0 | |
Silicon Labs Ember ZNet SDK | <7.4.0.0 | |
SiLabs Gecko SDK | <4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51393 has a medium severity due to the potential for an uncontrolled resource consumption vulnerability that can crash the device.
To fix CVE-2023-51393, upgrade to Silicon Labs Ember ZNet SDK version 7.4.0.0 or later, or Silicon Labs Gecko SDK version 4.4.0 or later.
CVE-2023-51393 affects Silicon Labs Ember ZNet SDK versions prior to 7.4.0.0 and Gecko SDK versions prior to 4.4.0.
An attacker can exploit CVE-2023-51393 to trigger a bus fault and crash the device due to resource allocation without limits.
Yes, CVE-2023-51393 can lead to denial of service conditions by causing the affected devices to crash.