Silicon Labs
First CVE: Nov 2, 2022Active for: 4 years
117
CVEs Published
More CVEs Published than 72% of tracked CNAs
23.4
Avg CVEs / Year
More Avg CVEs / Year than 72% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Silicon Labs as a CNA, 51.3% affect products that Silicon Labs develops as a vendor.
51.3%
48.7%
Self-reported: 60Third-party: 57
Of all the CVEs published that affect products developed by Silicon Labs, 62.5% are self-published by Silicon Labs as a CNA.
62.5%
37.5%
Self-published: 60Published by other CNAs: 36
Trends Over Time
The number and severity of CVEs published by Silicon Labs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2022
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Silicon Labs as a CNA, regardless of affected vendor or product.
117 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2815HIGH Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys | Jun 25, 2026 | 8.4 | 34 | NO | NO |
CVE-2026-8676HIGH An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. | May 26, 2026 | 8.8 | 34 | NO | NO |
CVE-2022-24942CRITICAL
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
| Nov 15, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-47151HIGH In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limit | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-47150HIGH In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this writ | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-47147HIGH In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. T | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2023-4041CRITICAL Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader | Aug 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-24937CRITICAL Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers. | Nov 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-8414CRITICAL Due to improper input validation, a buffer overflow vulnerability is present in
Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain
| Oct 17, 2025 | 9.4 | 30 | NO | NO |
CVE-2026-4930HIGH SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing).
D | Jun 25, 2026 | 7.1 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA117 CVEs
9%
38%
41%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local14 (12.0%)
Network56 (47.9%)
Unknown1 (0.9%)
Physical11 (9.4%)
Adjacent Network25 (21.4%)
Attack Complexity
Low104 (88.9%)
High12 (10.3%)
Unknown1 (0.9%)
User Interaction
None100 (85.5%)
Unknown1 (0.9%)
Required11 (9.4%)
Privileges Required
Low23 (19.7%)
High2 (1.7%)
None91 (77.8%)
Unknown1 (0.9%)
Exploit Exposure
Signals from CVEs in this cna scope (117 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Silicon Labs as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Silicon Labs as a CNA — matched by CVE ID, not by organization name.