- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 56 analyzed records
As of 09/11/2026, Silicon Labs recorded 19 security vulnerabilities in the last 90 days across 5 products, including 15 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, EmberZNet had the most security vulnerabilities in the Silicon Labs ecosystem, with 11 vulnerabilities—approximately 57.89% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-15419CP210x Driver Memory Corruption results in Arbitrary Code Execution | Exploitation statusNot known exploited | FixYes | Affected productsilabser.sys driver | Published09/10/2026 | SeverityHigh |
CVE-2026-15418CP210x Memory Leakage | Exploitation statusNot known exploited | FixYes | Affected productsilabser.sys driver | Published09/10/2026 | SeverityLow |
CVE-2026-15417CP210x Denial of Service | Exploitation statusNot known exploited | FixNot confirmed | Affected productsilabser.sys driver | Published09/10/2026 | SeverityMedium |
CVE-2026-17610RAIL 802.15.4 Mux missing ACK can lead to DoS | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published08/27/2026 | SeverityMedium |
CVE-2026-5706Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements | Exploitation statusNot known exploited | FixYes | Affected productBT Mesh SDK | Published08/27/2026 | SeverityHigh |
CVE-2026-6924Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path | Exploitation statusNot known exploited | FixYes | Affected productSilicon Labs Matter Github | Published07/23/2026 | SeverityHigh |
CVE-2026-6432Improper bounds validation in EmberZNet SDK | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published06/25/2026 | SeverityMedium |
CVE-2026-47154Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47153Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47152Level Control Move divide-by-zero in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47151Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47150IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47149Door Lock GetUserType invalid table index in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47148Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47147OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47146Color Control color-temperature assertion abort in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-47145Color Control hue/saturation assertion abort in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-4526Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 | Exploitation statusNot known exploited | FixYes | Affected productEmberZNet | Published06/25/2026 | SeverityHigh |
CVE-2026-2815Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys | Exploitation statusNot known exploited | FixYes | Affected productSiSDK | Published06/25/2026 | SeverityHigh |
CVE-2026-3290Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | Exploitation statusNot known exploited | FixYes | Affected productRS9116 SDK | Published05/14/2026 | SeverityHigh |
CVE-2025-2838Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko OS | Published03/26/2025 | SeverityMedium |
CVE-2025-2837Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko OS | Published03/26/2025 | SeverityHigh |
CVE-2024-9055DPA Countermeasures need reseeding | Exploitation statusNot known exploited | FixNot confirmed | Affected productSimplicity SDK | Published03/17/2025 | SeverityMedium |
CVE-2024-12975Silicon Labs CPC can leak information in full duplex SPI | Exploitation statusNot known exploited | FixYes | Affected productSimplicity SDK | Published03/07/2025 | SeverityLow |
CVE-2024-23937Silicon Labs Gecko OS Debug Interface Format String | Exploitation statusNot known exploited | FixYes | Affected productGecko OS | Published01/31/2025 | SeverityMedium |
CVE-2024-23973Silicon Labs Gecko OS HTTP GET Request Handling Stack-based Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productGecko OS | Published01/30/2025 | SeverityHigh |
CVE-2024-24731Silicon Labs Gecko OS http_download Stack-based Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productGecko OS | Published01/30/2025 | SeverityHigh |
CVE-2024-23938Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko OS | Published09/28/2024 | SeverityHigh |
CVE-2023-41093Loss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuse | Exploitation statusNot known exploited | FixNot confirmed | Affected productSimplicity SDK | Published07/12/2024 | SeverityLow |
CVE-2024-22472Long S0 frames received by 500 series Z-Wave devices may cause buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productZ-Wave SDK | Published05/07/2024 | SeverityHigh |
CVE-2023-51395Z-Wave S0 Decryption Vulnerability in End Devices | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ-Wave SDK | Published03/07/2024 | SeverityHigh |
CVE-2023-39541CVE-2023-39541 | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko Platform | Published02/20/2024 | SeverityMedium |
CVE-2023-39540CVE-2023-39540 | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko Platform | Published02/20/2024 | SeverityMedium |
CVE-2023-45318CVE-2023-45318 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published02/20/2024 | SeverityCritical |
CVE-2023-24585CVE-2023-24585 | Exploitation statusNot known exploited | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityHigh |
CVE-2023-25181CVE-2023-25181 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityCritical |
CVE-2023-28391CVE-2023-28391 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityCritical |
CVE-2023-27882CVE-2023-27882 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityCritical |
CVE-2023-28379CVE-2023-28379 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityCritical |
CVE-2023-31247CVE-2023-31247 | Exploitation statusPublic exploit | FixNot confirmed | Affected productGecko Platform | Published11/14/2023 | SeverityCritical |
CVE-2023-41094Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet | Published10/04/2023 | SeverityCritical |
CVE-2023-4041Second Stage Gecko Bootloader GBL Parser Buffer Overrun Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productGecko Bootloader | Published08/23/2023 | SeverityCritical |
CVE-2023-3110Buffer overflow in S0 Decryption on Unify Gateway | Exploitation statusNot known exploited | FixNot confirmed | Affected productUnify Gateway | Published06/21/2023 | SeverityCritical |
CVE-2023-0972Buffer overflow in S0 Decryption on Z/IP Gatweay | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway | Published06/21/2023 | SeverityCritical |
CVE-2023-0971Command Authentication Bypass in Z/IP Gateway | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway | Published06/21/2023 | SeverityCritical |
CVE-2023-0970Serial API Buffer Overflow in Z/IP Gateway | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway | Published06/21/2023 | SeverityHigh |
CVE-2023-0969Global read overflow in Z/IP Gateway | Exploitation statusNot known exploited | FixNot confirmed | Affected productZ/IP Gateway | Published06/21/2023 | SeverityLow |
CVE-2022-24937Malformed Zigbee packet causes Assert in EmberZNet 7.0.0 or earlier | Exploitation statusNot known exploited | FixYes | Affected productEmber ZNet | Published11/14/2022 | SeverityMedium |
CVE-2018-25029CVE-2018-25029 | Exploitation statusNot confirmed | FixNot confirmed | Affected productZ-Wave | Published02/04/2022 | SeverityUnknown |
CVE-2013-20003CVE-2013-20003 | Exploitation statusNot confirmed | FixYes | Affected productZ-Wave | Published02/04/2022 | SeverityUnknown |
CVE-2020-10137CVE-2020-10137 | Exploitation statusNot confirmed | FixNot confirmed | Affected productUZB-7 | Published01/09/2022 | SeverityUnknown |
CVE-2020-9061CVE-2020-9061 | Exploitation statusNot confirmed | FixNot confirmed | Affected product500 series | Published01/07/2022 | SeverityUnknown |
CVE-2020-9060CVE-2020-9060 | Exploitation statusNot confirmed | FixNot confirmed | Affected product500 series | Published01/07/2022 | SeverityUnknown |
CVE-2020-9059CVE-2020-9059 | Exploitation statusNot confirmed | FixNot confirmed | Affected product500 series | Published01/07/2022 | SeverityUnknown |
CVE-2020-9058CVE-2020-9058 | Exploitation statusNot confirmed | FixNot confirmed | Affected product500 series | Published01/07/2022 | SeverityUnknown |
CVE-2020-9057CVE-2020-9057 | Exploitation statusNot confirmed | FixNot confirmed | Affected product100 series | Published01/07/2022 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan