CVE-2023-41096
6.1
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.9 / Impact: 5.2
Source: NVD
Description
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules)
allows potential modification or extraction of network credentials stored in flash.
This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.
Affected (1)
Products: Silabs: Emberznet Sdk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.3.1.0 |
Related CWEs
CWE-311
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CWE-312
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
References (2)
Source: product-security@silabs.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.