CVE-2023-0971 is a critical logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier, enabling authentication bypass and remote administration of Z-Wave controllers. This vulnerability, rated 8.8 HIGH, allows an unauthenticated attacker on the adjacent network to fully compromise affected devices, leading to complete confidentiality, integrity, and availability loss, including S0/S2 encryption key recovery. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.18.01CPE matchmatch criteria | cpe:2.3:a:silabs:z\/ip_gateway_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.