ZDI-24-872: (Pwn2Own) Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-24737.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-872?
The severity of ZDI-24-872 is rated at 6.5 on the CVSS scale.
What type of attack does ZDI-24-872 enable?
ZDI-24-872 allows network-adjacent attackers to create a denial-of-service condition.
Is authentication required to exploit ZDI-24-872?
No, authentication is not required to exploit ZDI-24-872.
Which software is affected by ZDI-24-872?
ZDI-24-872 affects installations of Silicon Labs Gecko OS.
How can I mitigate the ZDI-24-872 vulnerability?
Mitigation details for ZDI-24-872 should be consulted in the vendor's advisories or updates.