CVE-2024-12975 Details
Description
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.
A buffer overread vulnerability has been identified in the CPC application of the Silicon Labs Gecko Platform. This issue occurs when the application is operating in full duplex SPI mode and receives an invalid packet over the SPI interface, leading to potential information leakage or memory corruption.
Users can upgrade to the latest version of the Silicon Labs Simplicity SDK, which includes the patched version of the Gecko Platform. The latest version can be downloaded from the Silicon Labs GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 7, 2025CISA-ADP
Assessed Mar 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.silabs.com/069Vm00000LWXMeIAP | [email protected] | Permission RequiredVendor |
| https://github.com/SiliconLabs/simplicity_sdk/releases | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-126 | Buffer Over-read | [email protected] |
Affected Products
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2025 | CVE Modified | [email protected] |
| Mar 7, 2025 | New CVE Received | [email protected] |
Volerion