silabs.com
- Total products in the ecosystem
- 48
- Total vulnerabilities (90 days)
- 11
en
Verify to analyze this security profile
As of 09/17/2026, silabs.com recorded 11 security vulnerabilities in the last 90 days across 4 products, including 8 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, WiseConnect had the most security vulnerabilities in the silabs.com ecosystem, with 6 vulnerabilities—approximately 54.55% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-16769RS9116W/SiWx917 plaintext pause encryption request causes DOS | Exploitation statusNot known exploited | FixYes | Affected productWiseCnnect | Published09/08/2026 | SeverityHigh |
CVE-2026-65936RS9116W/SiWx917 malformed packet with increased length field causes memory leak | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityMedium |
CVE-2026-65935Bypassing passkey entry in legacy pairing | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityHigh |
CVE-2026-65934BT122 plaintext pause encryption request causes DOS | Exploitation statusNot known exploited | FixYes | Affected productBT122 | Published08/13/2026 | SeverityHigh |
CVE-2026-65933BT122 malformed packet with increased length field causes memory leak | Exploitation statusNot known exploited | FixYes | Affected productBT122 | Published08/13/2026 | SeverityMedium |
CVE-2026-65932BT122 stops advertising | Exploitation statusNot known exploited | FixYes | Affected productBT122 | Published08/13/2026 | SeverityMedium |
CVE-2026-19293SMP security request | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityHigh |
CVE-2026-19292Bluetooth re-pairing with legitimate device can use lower security level | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityHigh |
CVE-2026-19291Bluetooth re-pairing can use a lower security level than previous | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityHigh |
CVE-2026-16101forced re-pairing with already bonded device | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published08/13/2026 | SeverityHigh |
CVE-2026-4930DPA Countermeasures weakening on Series 3 devices | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published06/25/2026 | SeverityHigh |
CVE-2026-8676 | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published05/26/2026 | SeverityHigh |
CVE-2025-14972Insufficient DPA countermeasure reseeding | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published05/15/2026 | SeverityMedium |
CVE-2025-11571Command Execution vulnerability in Simplicity Installer | Exploitation statusNot known exploited | FixYes | Affected productSimplicity Studio v5 | Published03/24/2026 | SeverityLow |
CVE-2025-14055Integer underflow in Secure NCP host | Exploitation statusNot known exploited | FixNot confirmed | Affected productSimplicity SDK, Gecko SDK | Published02/20/2026 | SeverityLow |
CVE-2025-14547ECJ-PAKE Integer Underflow Vulnerability in Silicon Labs PSA Crypto and SE Manager APIs | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published02/20/2026 | SeverityLow |
CVE-2026-0619Integer Wraparound DoS in Silicon Labs Matter Implementation | Exploitation statusNot known exploited | FixYes | Affected productSilicon Labs Matter | Published02/12/2026 | SeverityMedium |
CVE-2025-11004Reflected XSS vulnerability in Simplicity Device Manager tool | Exploitation statusNot known exploited | FixYes | Affected productSimplicity Device Manager | Published02/10/2026 | SeverityHigh |
CVE-2025-7432DPA countermeasures not reseeded under certain conditions | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published02/09/2026 | SeverityLow |
CVE-2025-12131Truncated 802.15.4 packet leads to denial of service | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet SDK | Published02/05/2026 | SeverityMedium |
CVE-2025-7964Zigbee Router Denial of Service | Exploitation statusNot known exploited | FixYes | Affected productSilicon Labs Zigbee Stack | Published01/30/2026 | SeverityCritical |
CVE-2025-10933Silicon Labs Z-Wave Protocol Controller Integer underflow vulnerability leads to out of bounds read | Exploitation statusNot known exploited | FixYes | Affected productZ-Wave Protocol Controller | Published01/05/2026 | SeverityMedium |
CVE-2025-12986Denial of Service Vulnerability in Silicon Labs WF200 and WGM160P Devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko SDK | Published12/04/2025 | SeverityMedium |
CVE-2025-10285Simplcity Device Manager exposes NTLMv2 hash | Exploitation statusNot known exploited | FixYes | Affected productSimplicity Studio V6 | Published12/04/2025 | SeverityHigh |
CVE-2025-4321DoS in RS9116W-WiSeConnect L2CAP protocol due to reception of malformed packets | Exploitation statusNot known exploited | FixNot confirmed | Affected productRS9116W | Published11/17/2025 | SeverityHigh |
CVE-2025-10693Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure | Exploitation statusNot known exploited | FixYes | Affected productSilicon Labs Z-Wave SDK | Published10/31/2025 | SeverityHigh |
CVE-2025-8414Zigbee Green Power Host Buffer Overflow Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published10/17/2025 | SeverityCritical |
CVE-2025-7448Man in the middle (MitM) attack vulnerability in Wi-SUN library | Exploitation statusNot known exploited | FixNot confirmed | Affected productWi-SUN Stack | Published09/12/2025 | SeverityHigh |
CVE-2025-1394Denial of Service (DoS) vulnerabilitiey in Zigbee library | Exploitation statusNot known exploited | FixYes | Affected productZigbee Stack | Published07/30/2025 | SeverityMedium |
CVE-2025-1221DoS in Zigbee device due to heavy traffic | Exploitation statusNot known exploited | FixYes | Affected productZigbee | Published07/30/2025 | SeverityMedium |
CVE-2025-2329High traffic causes corrupt SPI packets in OpenThread leading to denial of service | Exploitation statusNot known exploited | FixYes | Affected productOpenThread | Published07/25/2025 | SeverityMedium |
CVE-2025-3873Buffer overflow in Si91x crypto APIs | Exploitation statusNot known exploited | FixYes | Affected productWiseConnect | Published07/25/2025 | SeverityMedium |
CVE-2025-3301DPA Countermeasures Unavailable for Certain Cryptographic Operations on Series 2 Devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productSeries 2 SoCs and associated modules | Published04/29/2025 | SeverityLow |
CVE-2024-6351Malformed packet leads to denial of service in NWK/APS layer | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published01/28/2025 | SeverityMedium |
CVE-2024-9499Uncontrolled search path can lead to DLL hijacking in USBXpress Win 98SE Dev Kit installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productUSBXpress Win 98SE Dev Kit | Published01/24/2025 | SeverityHigh |
CVE-2024-9498Uncontrolled search path can lead to DLL hijacking in USBXpress SDK installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productUSBXpress SDK | Published01/24/2025 | SeverityHigh |
CVE-2024-9497Uncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productUSBXpress 4 SDK | Published01/24/2025 | SeverityHigh |
CVE-2024-9496Uncontrolled search path can lead to DLL hijacking in USBXpress Dev Kit installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productUSBXpress Dev Kit | Published01/24/2025 | SeverityHigh |
CVE-2024-9495Uncontrolled search path can lead to DLL hijacking in CP210x VCP Windows installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP210x VCP Windows | Published01/24/2025 | SeverityHigh |
CVE-2024-9494Uncontrolled search path can lead to DLL hijacking in CP210 VCP Win 2k installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP210 VCP Win 2k | Published01/24/2025 | SeverityHigh |
CVE-2024-9493Uncontrolled search path can lead to DLL hijacking in ToolStick installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productToolStick | Published01/24/2025 | SeverityHigh |
CVE-2024-9492Uncontrolled search path can lead to DLL hijacking in Flash Programming Utility installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productFlash Programming Utility | Published01/24/2025 | SeverityHigh |
CVE-2024-9491Uncontrolled search path can lead to DLL hijacking in Configuration Wizard 2 installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productConfiguration Wizard 2 | Published01/24/2025 | SeverityHigh |
CVE-2024-9490Uncontrolled search path can lead to DLL hijacking in Silicon Labs IDE installer | Exploitation statusNot known exploited | FixNot confirmed | Affected productSilicon Labs IDE (8-bit) | Published01/24/2025 | SeverityHigh |
CVE-2024-7322Dos in ZigBee device due to unsolicited encrypted rejoin response | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published01/15/2025 | SeverityMedium |
CVE-2024-6352Malformed packet leads to denial of service in APS layer | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published01/13/2025 | SeverityMedium |
CVE-2024-10106Ember ZNet buffer overflow in 'packet handoff' plugin | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet SDK | Published01/09/2025 | SeverityLow |
CVE-2024-6350EmberZNet malformed MAC layer packet leads to denial of service | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published01/08/2025 | SeverityMedium |
CVE-2024-8361DoS caused due to wrong hash length returned for SHA2/224 algorithm | Exploitation statusNot known exploited | FixYes | Affected productWiSeConnect SDK | Published01/07/2025 | SeverityHigh |
CVE-2024-7139Denial of Service in Silicon Labs RS9116 Bluetooth SDK | Exploitation statusNot known exploited | FixYes | Affected productRS9116 Bluetooth SDK | Published12/19/2024 | SeverityMedium |
CVE-2024-7138Denial of Service in Silicon Labs RS9116 Bluetooth SDK | Exploitation statusNot known exploited | FixYes | Affected productRS9116 Bluetooth SDK | Published12/19/2024 | SeverityMedium |
CVE-2024-7137Denial of Service in Silicon Labs RS9116 Bluetooth SDK | Exploitation statusNot known exploited | FixYes | Affected productRS9116 Bluetooth SDK | Published12/19/2024 | SeverityMedium |
CVE-2024-6657BLE peripheral DoS after few cycles of connect/disconnects | Exploitation statusNot known exploited | FixYes | Affected productEFR32 BLE SDK | Published10/11/2024 | SeverityMedium |
CVE-2024-2502Failure to update the tamper reset cause register when a tamper event occurs | Exploitation statusNot known exploited | FixYes | Affected productSE Firmware | Published08/29/2024 | SeverityLow |
CVE-2024-3017Denial of service in multi-protocol gateway - Zigbee + Thread | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published06/27/2024 | SeverityMedium |
CVE-2024-3043Zigbee co-ordinator realignment packet may lead to denial of service | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet SDK | Published06/27/2024 | SeverityHigh |
CVE-2024-4013Failure to update BT Mesh Replay Protection List | Exploitation statusNot known exploited | FixYes | Affected productGecko SDK | Published06/06/2024 | SeverityMedium |
CVE-2024-3052Z/IP Gateway S2 Nonce Get Denial of Service Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productZ/IP Gateway SDK | Published04/26/2024 | SeverityHigh |
CVE-2024-3051Z/IP Gateway Device Reset Locally Denial of Service Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway SDK | Published04/26/2024 | SeverityHigh |
CVE-2023-51393Potential DoS due to BusFault and Assert in Ember ZNet legacy packet buffer | Exploitation statusNot known exploited | FixNot confirmed | Affected productEmber ZNet SDK | Published02/23/2024 | SeverityMedium |
CVE-2023-51394Potential DoS for EFR32xxx parts in high traffic environments due to null buffer dereference / crash | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet SDK | Published02/23/2024 | SeverityMedium |
CVE-2023-51392Silicon Labs EFR32xxx parts with classic key storage do not use hardware accelerated AES-CCM | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet SDK | Published02/23/2024 | SeverityMedium |
CVE-2023-6640Silicon Labs PC Controller v5.54.0 and Earlier Denial of Service Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productPC Controller | Published02/21/2024 | SeverityMedium |
CVE-2023-6533Silicon Labs PC Controller Denial of Service Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productPC Controller | Published02/21/2024 | SeverityMedium |
CVE-2024-22473Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productGSDK | Published02/21/2024 | SeverityMedium |
CVE-2024-0240Silicon Labs EFR32 Bluetooth stack denial of service when sending notifications to multiple clients | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published02/15/2024 | SeverityMedium |
CVE-2023-6874Zigbee Unauthenticated DoS via NWK Sequence number manipulation | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published02/05/2024 | SeverityHigh |
CVE-2023-6387Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published02/02/2024 | SeverityHigh |
CVE-2023-5138Glitch detection not active by default in Silicon Labs Secure Vault High devices | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published01/03/2024 | SeverityMedium |
CVE-2023-4280Unvalidated input in Silicon Labs TrustZone implementation leads to accessing Trusted memory region | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published01/02/2024 | SeverityCritical |
CVE-2023-41097Potential Timing vulnerability in CBC PKCS7 padding calculations | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published12/21/2023 | SeverityMedium |
CVE-2023-4020Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memory | Exploitation statusNot confirmed | FixYes | Affected productGSDK | Published12/15/2023 | SeverityCritical |
CVE-2023-5310Z-Wave Denial of Service caused by Stream of Packets | Exploitation statusNot known exploited | FixYes | Affected productGecko SDK | Published12/15/2023 | SeverityMedium |
CVE-2023-4489Z/IP Gateway Use of Uninitialized PRNG when Generating S0 Encryption Key | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway SDK | Published12/14/2023 | SeverityMedium |
CVE-2023-41096Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productEmber ZNet SDK | Published10/26/2023 | SeverityMedium |
CVE-2023-41095Keys Stored in Plaintext on Secure Vault High for Silabs OpenThread devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productOpenThread SDK | Published10/26/2023 | SeverityMedium |
CVE-2023-3487Integer overflow in Silicon Labs Gecko Bootloader leads to unbounded memory access | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published10/20/2023 | SeverityHigh |
CVE-2023-3024Bluetooth LE segmented 'prepare write response' packet may lead to out-of-bounds memory access | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published09/29/2023 | SeverityMedium |
CVE-2023-3488Uninitialized variable in Gecko Bootloader can leak secure stack | Exploitation statusNot known exploited | FixYes | Affected productGecko Bootloader | Published07/28/2023 | SeverityLow |
CVE-2023-2747Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published06/15/2023 | SeverityLow |
CVE-2023-2683Connection update while closing connection may lead to denial-of-service | Exploitation statusNot known exploited | FixYes | Affected productBluetooth SDK | Published06/15/2023 | SeverityMedium |
CVE-2023-2686 | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published06/15/2023 | SeverityCritical |
CVE-2023-2687 | Exploitation statusNot known exploited | FixYes | Affected productGecko SDK | Published06/02/2023 | SeverityLow |
CVE-2023-32100Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityMedium |
CVE-2023-32099Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityMedium |
CVE-2023-32098Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityMedium |
CVE-2023-32097Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityLow |
CVE-2023-32096Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityLow |
CVE-2023-2481Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityMedium |
CVE-2023-1132Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityMedium |
CVE-2023-0965Key duplication in GSDK | Exploitation statusNot known exploited | FixYes | Affected productGecko Platform | Published05/18/2023 | SeverityLow |
CVE-2023-0775Bluetooth LE Invalid prepare write request command leads to denial of service | Exploitation statusNot known exploited | FixYes | Affected productGSDK | Published03/28/2023 | SeverityMedium |
CVE-2023-1262Missing MAC layer security in Wi-SUN Linux Border Router | Exploitation statusNot known exploited | FixYes | Affected productWi-SUN Linux Border Router | Published03/21/2023 | SeverityHigh |
CVE-2023-1261Missing MAC layer security in Wi-SUN SDK | Exploitation statusNot known exploited | FixYes | Affected productWi-SUN SDK | Published03/21/2023 | SeverityHigh |
CVE-2022-24939Malformed Zigbee packet with invalid destination address causes Assert | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet | Published11/17/2022 | SeverityMedium |
CVE-2022-24938Malformed Zigbee packet causes Assert in EmberZNet 7.0.1 or earlier | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet | Published11/14/2022 | SeverityMedium |
CVE-2022-24942Heap-based buffer overflow in MicriumOS HTTP Server allows potential remote code execution | Exploitation statusPublic exploit | FixYes | Affected productGecko Platform | Published11/02/2022 | SeverityCritical |
CVE-2022-24936Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devices | Exploitation statusPublic exploit | FixYes | Affected productGecko Bootloader | Published11/02/2022 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan