CVE-2023-0971
21.06.2023, 20:15
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.Enginsight
Vendor | Product | Version |
---|---|---|
silabs | z\/ip_gateway_sdk | 𝑥 ≤ 7.18.01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-268 - Privilege ChainingTwo distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.