Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSilabs Emberznet
APPSilabs7.2.0 – 7.2.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-41094CRITICAL10.0PL ✓same product
Silicon Labs EmberZNet — dodanie urządzenia poza zasięgiem TouchLink
CVE-2026-47146HIGH7.1same product
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the proce...
CVE-2026-4526HIGH7.1PL ✓same product
Odmowa usługi przez out-of-bounds read w Silabs EmberZNet (ZCL)
CVE-2026-47145HIGH7.1same product
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the proce...
CVE-2026-47147HIGH7.1PL ✓same product
Out-of-bounds read w parserze OTA w Silabs EmberZNet