Gecko Software Development Kit

Vendor:

First CVE: Nov 18, 2022 · Active for 3 years

30
Total CVEs
More Total CVEs than 96% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gecko Software Development Kit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2022
3 years ago
Most Recent CVE
Feb 21, 2024
885 days ago

CVE Severity & Scoring

Gecko Software Development Kit30 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local3 (10.0%)
Network21 (70.0%)
Unknown0 (0.0%)
Physical1 (3.3%)
Adjacent Network5 (16.7%)
Attack Complexity
Low29 (96.7%)
High1 (3.3%)
Unknown0 (0.0%)
User Interaction
None29 (96.7%)
Unknown0 (0.0%)
Required1 (3.3%)
Privileges Required
Low2 (6.7%)
High0 (0.0%)
None28 (93.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to
Nov 14, 20239.830NONO
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to co
Nov 14, 20239.829NONO
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
Jun 15, 20239.829NONO
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arb
Feb 20, 20249.828NONO
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted re
Jan 2, 20249.827NONO
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code exe
Nov 14, 20239.827NONO
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code exe
Nov 14, 20239.827NONO
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbit
Nov 14, 20239.827NONO
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption.
Nov 14, 20239.827NONO
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
Feb 2, 20247.525NONO

Exploit Exposure

Signals from CVEs in this product scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (30 CVEs).

Media Mentions

Signals from CVEs in this product scope (30 CVEs).

Top CNAs Publishing CVEs For Gecko Software Development Kit

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.1.116.50.3%00
5.1.016.50.3%00
4.3.2.019.81.8%00
4.3.169.81.6%00