PT-2023-29314 · Silicon · Z/Ip Gateway

CVE-2023-4489

·

Publicado

2023-12-14

·

Atualizado

2024-09-27

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK versions prior to 7.18.3
Description The first S0 encryption key is generated with an uninitialized PRNG, making the first S0 key generated at startup predictable. This potentially allows network key prediction and unauthorized S0 network access.
Recommendations For versions prior to 7.18.3, update to a version that initializes the PRNG properly to prevent predictable S0 key generation. As a temporary workaround, consider regenerating the S0 encryption key after startup to minimize the risk of exploitation.

Correção

Use of Uninitialized Resource

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-4489

Produtos afetados

Z/Ip Gateway