PT-2023-29314 · Silicon · Z/Ip Gateway

Published

2023-12-14

·

Updated

2024-09-27

·

CVE-2023-4489

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK versions prior to 7.18.3
Description The first S0 encryption key is generated with an uninitialized PRNG, making the first S0 key generated at startup predictable. This potentially allows network key prediction and unauthorized S0 network access.
Recommendations For versions prior to 7.18.3, update to a version that initializes the PRNG properly to prevent predictable S0 key generation. As a temporary workaround, consider regenerating the S0 encryption key after startup to minimize the risk of exploitation.

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2023-4489

Affected Products

Z/Ip Gateway