PatchSiren

Silicon Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Silicon Labs CVE published 2026-08-28

CVE-2026-5706

Bluetooth Mesh SDK vulnerability CVE-2026-5706 allows remote code execution via malformed extended advertisements from devices that have joined the network, impacting provisioners supporting extended advertisements. Immediate attention is required from Bluetooth Mesh SDK users, network administrators, and IoT security teams to review configurations and update to the latest SDK version to prevent stack cor [truncated]

MEDIUM Silicon Labs CVE published 2026-08-28

CVE-2026-17610

A denial of service vulnerability exists in SiSDK v2026.6.0 and earlier, specifically for EFR32MG24 and EFR32MG26 devices running concurrent multiprotocol Zigbee and Thread under high network traffic loads. This issue may cause a dropped ACK. Defenders should verify affected versions, assess exposure, and monitor for potential denial of service. Verification of affected SiSDK versions and device configura [truncated]

HIGH Silicon Labs CVE published 2026-07-23

CVE-2026-6924

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated. The impacted repository was deprecated before the discovery of the vulnerability, which affects Matter code deployments using SiWx917. Defen [truncated]

CRITICAL Silicon Labs CVE published 2025-05-13

CVE-2023-4041

CVE-2023-4041 is a critical issue disclosed in Schneider Electric and CISA advisories on 2025-05-13 for PrismaSeT Active - Wireless Panel Server. The source advisory states the product is at end of life and that the risk can be reduced only through mitigations. The underlying weakness is described as a buffer overflow/out-of-bounds write and lack of integrity checking in a firmware update file parser, wit [truncated]