CVE-2023-4489
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.
Affected (1)
Products: Silabs: Z/ip Gateway Sdk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.18.03 |
Related CWEs
CWE-1279
Cryptographic Operations are run Before Supporting Units are Ready
Performing cryptographic operations without ensuring that the supporting inputs are ready to supply valid data may compromise the cryptographic result.
CWE-908
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
References (4)
Source: product-security@silabs.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.