← Vulnerability feed

Vulnerability record · CVE-2022-24937 · published 14 November 2022

CVE-2022-24937: Silabs emberznet memory buffer overflow vulnerability

SSilabs · Emberznet

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

9.8 CVSS 3.1 Critical EPSS 0.69% · top 49.0% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24937 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51392Silabs emberznet broken cryptographic algorithm vulnerabilityEmber ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of …EPSS 0.24%9.8CVE-2023-41094Silabs emberznet vulnerabilityTouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effec…EPSS 0.58%7.5CVE-2023-51393Silabs emberznet allocation without limits vulnerabilityDue to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v…EPSS 0.52%7.5CVE-2023-51394Silabs emberznet null pointer dereference vulnerabilityHigh traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.EPSS 0.52%7.5CVE-2022-24938Silabs emberznet memory buffer overflow vulnerabilityA malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.EPSS 0.75%7.1CVE-2026-4526Silabs emberznet out-of-bounds read vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. …EPSS 0.44%7.1CVE-2026-47149Silabs emberznet out-of-bounds read vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process…EPSS 0.44%7.1CVE-2026-47150Silabs emberznet out-of-bounds write vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2022-24937), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.