Lucene search

K
cvelistSilabsCVELIST:CVE-2023-41094
HistoryOct 04, 2023 - 8:01 p.m.

CVE-2023-41094 Touchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNet

2023-10-0420:01:16
CWE-940
Silabs
www.cve.org
6
cve-2023-41094
ember znet
touchlink
authentication bypass
resource operation
packet timeout
range expiration
device pairing

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.001

Percentile

43.7%

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration

This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "TouchLink"
    ],
    "platforms": [
      "32 bit",
      "ARM"
    ],
    "product": "Ember ZNet",
    "repo": "https://github.com/SiliconLabs/gecko_sdk",
    "vendor": "Silicon Labs",
    "versions": [
      {
        "lessThanOrEqual": "7.1.5",
        "status": "affected",
        "version": "7.1.3",
        "versionType": "7.1.x"
      },
      {
        "lessThanOrEqual": "7.2.3",
        "status": "affected",
        "version": "7.2.0",
        "versionType": "7.2.x"
      },
      {
        "status": "unaffected",
        "version": "7.3.0"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for CVELIST:CVE-2023-41094