CVE-2024-6350 Details
Description
A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.
A buffer overflow vulnerability has been identified in the Silicon Labs Simplicity SDK, specifically within the 802.15.4 packet processing component. This vulnerability allows for the creation of malformed 802.15.4 packets that, when processed, cause a buffer overflow. The overflow triggers an assertion failure, leading to a denial-of-service condition. Fortunately, this error condition is automatically cleared by a watchdog reset.
Users can upgrade to the latest version of the Silicon Labs Simplicity SDK to address this vulnerability. The patched version is included in the official release on the Silicon Labs GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 8, 2025CISA-ADP
Assessed Jan 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.silabs.com/069Vm00000HtvDgIAJ | [email protected] | Permission RequiredVendor |
| https://github.com/SiliconLabs/simplicity_sdk/releases | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Silicon Labs Simplicity SDK | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2025 | New CVE Received | [email protected] |
Volerion