CVE-2023-6640: Silicon Labs PC Controller v5.54.0 and Earlier Denial of Service Vulnerability
Published Feb 21, 2024
·Updated
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.
Affected Software
2 affected components
Silabs Z-wave Pc-based Controller<=5.54
Silicon Labs PC Controller<5.54.0
Event History
Feb 21, 2024
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6640?
CVE-2023-6640 has been classified with a high severity due to the potential for Denial of Service attacks.
2
How do I fix CVE-2023-6640?
To mitigate CVE-2023-6640, update to Silicon Labs PC Controller version 5.54.1 or later.
3
What types of systems are affected by CVE-2023-6640?
CVE-2023-6640 affects Silicon Labs PC Controller versions up to 5.54.0.
4
What is the nature of the vulnerability in CVE-2023-6640?
CVE-2023-6640 allows attackers to send malformed S2 Nonce Get Command Class packets which can crash the PC Controller application.
5
When was CVE-2023-6640 disclosed?
CVE-2023-6640 was publicly disclosed in October 2023.