Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSilabs Emberznet
APPSilabs7.2.0 – 7.2.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2023-41094CRITICAL10.0PL ✓ten sam produkt
Silicon Labs EmberZNet — dodanie urządzenia poza zasięgiem TouchLink
CVE-2026-47146HIGH7.1ten sam produkt
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the proce...
CVE-2026-4526HIGH7.1PL ✓ten sam produkt
Odmowa usługi przez out-of-bounds read w Silabs EmberZNet (ZCL)
CVE-2026-47145HIGH7.1ten sam produkt
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the proce...
CVE-2026-47147HIGH7.1PL ✓ten sam produkt
Out-of-bounds read w parserze OTA w Silabs EmberZNet