PT-2023-29314 · Silicon · Z/Ip Gateway
CVE-2023-4489
·
Publicado
2023-12-14
·
Atualizado
2024-09-27
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK versions prior to 7.18.3
Description
The first S0 encryption key is generated with an uninitialized PRNG, making the first S0 key generated at startup predictable. This potentially allows network key prediction and unauthorized S0 network access.
Recommendations
For versions prior to 7.18.3, update to a version that initializes the PRNG properly to prevent predictable S0 key generation.
As a temporary workaround, consider regenerating the S0 encryption key after startup to minimize the risk of exploitation.
Correção
Use of Uninitialized Resource
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Z/Ip Gateway