CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “silabs”

85 vulnerabilities found for “silabs”

Page 1 of 5

CVE-2025-12131
MEDIUM6.5

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

silabs / simplicity_software_development_kit
Adjacent
Published Feb 5, 2026
Page 1 of 5
CVE-2023-41093
LOW3.1

Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

silabs / bluetooth_low_energy_software_development_kit
Adjacent
Published Jul 12, 2024
CVE-2023-6533
MEDIUM6.5

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier.

silabs / z-wave_pc-based_controller
Adjacent
Published Feb 21, 2024
CVE-2023-6640
MEDIUM6.5

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

silabs / z-wave_pc-based_controller
Adjacent
Published Feb 21, 2024
CVE-2023-41096
MEDIUM6.8

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

silabs / emberznet_sdk
Physical
Published Oct 26, 2023
CVE-2023-3487
HIGH7.7

An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when reading from or writing to storage slots.

silabs / gecko_bootloader
Local
Published Oct 20, 2023
CVE-2023-4041
CRITICAL9.8

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This issue affects "Standalone" and "Application" versions of Gecko Bootloader.

silabs / gecko_bootloader+1
Network
Published Aug 23, 2023
CVE-2023-2683
MEDIUM5.3

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

silabs / bluetooth_low_energy_software_development_kit
Adjacent
Published Jun 15, 2023
CVE-2023-1261
HIGH8.2

Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.

silabs / wi-sun_software_development_kit
Network
Published Mar 21, 2023
CVE-2022-24939
MEDIUM5.7

 A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

silabs / gecko_software_development_kit+1
Adjacent
Published Nov 18, 2022
CVE-2022-24942
CRITICAL9.1

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

silabs / micrium_uc-http
Network
Published Nov 15, 2022
CVE-2022-24936
HIGH8.3

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

silabs / gecko_bootloader
Adjacent
Published Nov 2, 2022
CVE-2022-24611
MEDIUM6.5

Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.

silabs / zm5202_firmware+4
Adjacent
Published May 17, 2022
CVE-2018-25029
HIGH8.1

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.

silabs / zgm130s037hgn_firmware+4
Adjacent
Published Feb 4, 2022
CVE-2013-20003
HIGH8.3

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to spoof Z-Wave traffic.

silabs / zgm130s037hgn_firmware+4
Adjacent
Published Feb 4, 2022
CVE-2020-9057
HIGH8.8

Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware upgrades cannot directly address this vulnerability as it is an issue with the Z-Wave specification for these legacy chipsets. One way to protect against this vulnerability is to use 500 or 700 series chipsets that support Security 2 (S2) encryption. As examples, the Linear WADWAZ-1 version 3.43 and WAPIRZ-1 version 3.43 (with 300 series chipsets) are vulnerable.

linear / wadwaz-1+4
Adjacent
Published Jan 10, 2022
CVE-2020-13582
HIGH7.5

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

silabs / micrium_uc-http
Network
Published Jan 26, 2021
CVE-2020-15531
HIGH8.8

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

silabs / bluetooth_low_energy_software_development_kit
Adjacent
Published Aug 20, 2020
CVE-2020-15532
MEDIUM6.5

Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.

silabs / bluetooth_low_energy_software_development_kit
Adjacent
Published Aug 20, 2020
CVE-2018-19983
MEDIUM6.5

An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided "Nonce Get (0x98 0x81)" frames. The reason for dividing the "Nonce Get" frame is that, in security version S0, when a node receives a "Nonce Get" frame, the node produces a random new nonce and sends it to the Src node of the received "Nonce Get" frame. After the nonce value is generated and transmitted, the node transitions to wait mode. At this time, when "Nonce Get" is received again, the node discards the previous nonce value and generates a random nonce again. Therefore, because the frame is encrypted with previous nonce value, the received normal frame cannot be decrypted.

silabs / z-wave_s0_firmware+1
Adjacent
Published Dec 9, 2018