A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.
An exception is thrown from a function, but it is not caught.
Link | Tags |
---|---|
https://github.com/SiliconLabs/gecko_sdk/releases | release notes |
https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000005E7EIAU?%20operationContext=S1 | vendor advisory permissions required |