ZDI-CAN-23392: ZDI-24-872: (Pwn2Own) Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-24737.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23392?
ZDI-CAN-23392 has been assigned a CVSS rating of 6.5, indicating a medium severity.
What kind of attack does ZDI-CAN-23392 allow?
ZDI-CAN-23392 allows network-adjacent attackers to create a denial-of-service condition on affected installations.
Is authentication required to exploit ZDI-CAN-23392?
No, authentication is not required to exploit the vulnerability ZDI-CAN-23392.
Which software is affected by ZDI-CAN-23392?
ZDI-CAN-23392 affects installations of Silicon Labs Gecko OS.
How can I mitigate the risk of ZDI-CAN-23392?
To mitigate ZDI-CAN-23392, ensure that all installations of Silicon Labs Gecko OS are updated to the latest version provided by the vendor.