Silicon Labs Ember ZNet
cpe:2.3:a:silabs:emberznet:*:*:*:*:*:*:*, +2 more
- >= 8.0.0.0, < 8.0.1.0
A buffer overflow vulnerability has been identified in the NWK/APS layer of the Ember ZNet stack, specifically within the Zigbee SDK version 8.0.0.0. This vulnerability arises from the processing of malformed packets, which can lead to an assertion failure.
Exploitation of this vulnerability causes a buffer overflow, which can potentially be leveraged to execute arbitrary code or cause a denial-of-service condition by crashing the application.
Users can upgrade to Zigbee EmberZNet SDK version 8.1.2.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.