CVE-2023-4489
14.12.2023, 23:15
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.Enginsight
Vendor | Product | Version |
---|---|---|
silabs | z\/ip_gateway_sdk | 𝑥 ≤ 7.18.03 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1279 - Cryptographic Operations are run Before Supporting Units are ReadyPerforming cryptographic operations without ensuring that the supporting inputs are ready to supply valid data may compromise the cryptographic result.
- CWE-908 - Use of Uninitialized ResourceThe software uses or accesses a resource that has not been initialized.
References