CVE-2023-6533: Silicon Labs PC Controller Denial of Service Vulnerability
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6533?
CVE-2023-6533 is classified as a medium severity vulnerability.
How do I fix CVE-2023-6533?
To mitigate CVE-2023-6533, update the affected Silabs Z-wave PC-based Controller to the latest version beyond 5.54.
What type of vulnerability is CVE-2023-6533?
CVE-2023-6533 is a command injection vulnerability that affects the handling of malformed Device Reset Locally Command Class packets.
Which versions are affected by CVE-2023-6533?
CVE-2023-6533 affects versions of the Silabs Z-wave PC-based Controller up to and including version 5.54.
Where can I find more details about CVE-2023-6533?
Additional information about CVE-2023-6533 can be found in the official Silicon Labs community discussions.