📦 Gecko Software Development Kit

by Silabs

🔍 What is Gecko Software Development Kit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-45318

CRITICAL CVSS 10.0 Feb 20, 2024

This critical vulnerability allows remote attackers to execute arbitrary code on systems running Weston Embedded uC-HTTP server by sending specially crafted network packets. The heap-based buffer over...

CVE-2023-4280

CRITICAL CVSS 9.3 Jan 2, 2024

This vulnerability allows attackers to bypass TrustZone memory isolation in Silicon Labs Gecko SDK, enabling unauthorized access to trusted memory regions from untrusted areas. It affects systems usin...

CVE-2023-31247

CRITICAL CVSS 9.0 Nov 14, 2023

A memory corruption vulnerability in Weston Embedded uC-HTTP v3.01.01's HTTP Server Host header parsing allows remote code execution via specially crafted network packets. This affects systems running...

CVE-2023-28379

CRITICAL CVSS 9.0 Nov 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Weston Embedded uC-HTTP v3.01.01 by sending specially crafted HTTP packets. It affects any device or application...

CVE-2023-25181

CRITICAL CVSS 9.0 Nov 14, 2023

This CVE describes a heap-based buffer overflow vulnerability in Weston Embedded uC-HTTP v3.01.01's HTTP server functionality. Attackers can send specially crafted network packets to trigger arbitrary...

CVE-2023-2686

CRITICAL CVSS 9.8 Jun 15, 2023

A buffer overflow vulnerability in the Wi-Fi Commissioning example code in Silicon Labs Gecko SDK allows attackers to write arbitrary payloads onto the stack. This affects devices using Gecko SDK v4.2...

CVE-2023-6874

HIGH CVSS 7.5 Feb 5, 2024

CVE-2023-6874 is a denial of service vulnerability in Silicon Labs Ember ZNet wireless networking stack versions before 7.4.0. Attackers can manipulate NWK sequence numbers to cause network disruption...

CVE-2023-24585

HIGH CVSS 7.7 Nov 14, 2023

An out-of-bounds write vulnerability in Weston Embedded uC-HTTP v3.01.01 allows remote attackers to cause memory corruption via specially crafted HTTP packets. This affects systems using the vulnerabl...

CVE-2023-0775

MEDIUM CVSS 6.5 Mar 28, 2023

This vulnerability in Silicon Labs Gecko SDK Bluetooth LE stack allows an attacker to send a malformed 'prepare write request' command that causes memory exhaustion, leading to denial-of-service by pr...