CVE-2025-3873: Buffer overflow in Si91x crypto APIs
Published Jul 25, 2025
·Updated
The following APIs for the Silcon Labs SiWx91x prior to vesion 3.4.0 failed to check the size of the output buffer of the caller which could lead to data corruption on the host (Cortex-M4) application.
slsi91xaes slsi91xgcm slsi91xccm slsi91xsha
Affected Software
1 affected component
Silicon Labs SiWx91x<3.4.0
Event History
Jul 25, 2025
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3873?
CVE-2025-3873 has a medium severity level due to potential data corruption risks.
2
How do I fix CVE-2025-3873?
To fix CVE-2025-3873, update the affected SiWx91x software to version 3.4.0 or later.
3
Which APIs are affected by CVE-2025-3873?
CVE-2025-3873 impacts the sl_si91x_aes, sl_si91x_gcm, sl_si91x_ccm, and sl_si91x_sha APIs.
4
What happens if I do not address CVE-2025-3873?
Failing to address CVE-2025-3873 may lead to data corruption in applications using the affected APIs.
5
What is the affected software for CVE-2025-3873?
The affected software for CVE-2025-3873 is the Silicon Labs SiWx91x prior to version 3.4.0.