PT-2023-29314 · Silicon · Z/Ip Gateway
Published
2023-12-14
·
Updated
2024-09-27
·
CVE-2023-4489
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK versions prior to 7.18.3
Description
The first S0 encryption key is generated with an uninitialized PRNG, making the first S0 key generated at startup predictable. This potentially allows network key prediction and unauthorized S0 network access.
Recommendations
For versions prior to 7.18.3, update to a version that initializes the PRNG properly to prevent predictable S0 key generation.
As a temporary workaround, consider regenerating the S0 encryption key after startup to minimize the risk of exploitation.
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Z/Ip Gateway