Silicon Labs Gecko OS Debug Interface Format String Information Disclosure Vulnerability

Vulnerability

A vulnerability in the debug interface of Silicon Labs Gecko OS allows network-adjacent attackers to disclose sensitive information. The issue arises from improper validation of user-supplied strings used as format specifiers, which could be exploited in conjunction with other vulnerabilities to execute arbitrary code on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure and potentially allow for arbitrary code execution on the affected device.

Remediation

Silicon Labs has released an update to address this vulnerability. Details about the update can be found on the Silicon Labs community page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.