First published: Wed Feb 21 2024(Updated: )
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Z-wave PC-based Controller | <=5.54 | |
Silabs Z-wave PC-based Controller | <5.54.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6640 has been classified with a high severity due to the potential for Denial of Service attacks.
To mitigate CVE-2023-6640, update to Silicon Labs PC Controller version 5.54.1 or later.
CVE-2023-6640 affects Silicon Labs PC Controller versions up to 5.54.0.
CVE-2023-6640 allows attackers to send malformed S2 Nonce Get Command Class packets which can crash the PC Controller application.
CVE-2023-6640 was publicly disclosed in October 2023.