← Vulnerability feed

Vulnerability record · CVE-2023-51392 · published 23 February 2024

CVE-2023-51392: Silabs emberznet broken cryptographic algorithm vulnerability

SSilabs · Emberznet

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

9.8 CVSS 3.1 Critical EPSS 0.24% · top 85.9% CWE-1240 · CWE-1240CWE-327 · Broken cryptographic algorithm
9.8CVSS 3.1 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-51392 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-41094Silabs emberznet vulnerabilityTouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effec…EPSS 0.58%9.8CVE-2022-24937Silabs emberznet memory buffer overflow vulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.EPSS 0.69%7.5CVE-2023-51393Silabs emberznet allocation without limits vulnerabilityDue to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v…EPSS 0.52%7.5CVE-2023-51394Silabs emberznet null pointer dereference vulnerabilityHigh traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.EPSS 0.52%7.5CVE-2022-24938Silabs emberznet memory buffer overflow vulnerabilityA malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.EPSS 0.75%7.1CVE-2026-4526Silabs emberznet out-of-bounds read vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. …EPSS 0.44%7.1CVE-2026-47149Silabs emberznet out-of-bounds read vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process…EPSS 0.44%7.1CVE-2026-47150Silabs emberznet out-of-bounds write vulnerabilityIn EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2023-51392), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.