CVE-2023-6874: Zigbee Unauthenticated DoS via NWK Sequence number manipulation
Published Feb 5, 2024
·Updated
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
Affected Software
1 affected component
Silabs Gecko Software Development Kit<4.4.0
Event History
Feb 5, 2024
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6874?
CVE-2023-6874 has a severity rating indicating it poses a risk of denial of service attacks.
2
How do I fix CVE-2023-6874?
To resolve CVE-2023-6874, it is recommended to upgrade to Ember ZNet version 7.4.0 or later.
3
What is the impact of CVE-2023-6874?
The impact of CVE-2023-6874 is that it allows an attacker to manipulate network sequence numbers, potentially resulting in a denial of service.
4
Who is affected by CVE-2023-6874?
CVE-2023-6874 affects users of the Silicon Labs Gecko Software Development Kit prior to version 7.4.0.
5
What type of vulnerability is CVE-2023-6874?
CVE-2023-6874 is classified as a denial of service vulnerability.