CVE-2023-4489 is a critical vulnerability affecting Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier, where the initial S0 encryption key is generated using an uninitialized pseudo-random number generator. This flaw allows for predictable network key generation, potentially leading to unauthorized S0 network access. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, posing a high risk to confidentiality, integrity, and availability. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.18.03CPE matchmatch criteria | cpe:2.3:a:silabs:z\/ip_gateway_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.