CVE-2024-23973 Details
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP GET requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
A remote code execution vulnerability has been identified in Silicon Labs Gecko OS. This issue arises from improper validation of user-supplied data lengths in HTTP GET requests, allowing network-adjacent attackers to execute arbitrary code on the affected device. No authentication is required to exploit this vulnerability.
Silicon Labs has released an update to address this vulnerability. Details about the update can be found on the Silicon Labs community page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.silabs.com/a45Vm0000000Atp | [email protected] | Permissions Required |
| https://www.zerodayinitiative.com/advisories/ZDI-24-873/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| silabs gecko os | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | Modified Analysis | [email protected] |
| Aug 26, 2025 | CVE Modified | CISA-ADP |
| Jul 7, 2025 | Initial Analysis | [email protected] |
| Jun 30, 2025 | CVE Modified | [email protected] |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | New CVE Received | [email protected] |