Silicon Labs develops wireless connectivity platforms and embedded software development kits spanning Gecko microcontroller firmware, Z-Wave protocol stacks, and related IoT and smart-home components, with a footprint that extends across connected devices in industrial and consumer deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and buffer-management demands of low-level firmware and protocol implementations. The recurring exposure centers on products including the Gecko Software Development Kit and Z-Wave Software Development Kit, and concentrates through weakness classes such as out-of-bounds writes, improper memory-buffer restrictions, and compiler-optimization issues that strip safety-critical buffer-clearing operations. Defenders should track this vendor's firmware advisories closely and prioritize updates for internet-exposed or remote-management-enabled wireless devices; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Silicon Labs over time
Of all the CVEs published by Silicon Labs as a CNA, 51.3% affect products that Silicon Labs develops as a vendor.
Of all the CVEs published that affect products developed by Silicon Labs, 62.5% are self-published by Silicon Labs as a CNA.
Signals from CVEs in this vendor scope (96 CVEs).
96 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24942CRITICAL
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
| Nov 15, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-47151HIGH In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limit | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-47150HIGH In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this writ | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-47147HIGH In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. T | Jun 25, 2026 | 7.1 | 31 | NO | NO |
CVE-2023-4041CRITICAL Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader | Aug 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-24937CRITICAL Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers. | Nov 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-27882CRITICAL A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to | Nov 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-27630CRITICAL In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random. | Oct 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-51392CRITICAL Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differentia | Feb 23, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-31247CRITICAL A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to co | Nov 14, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (96 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Silicon Labs.
Media articles that mention a CVE ID that affects a product developed by Silicon Labs — matched by CVE ID, not by vendor name.