VulnerabilityModified
CVE-2023-2687
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.
LOW 3.3EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787, CWE-131
- Affected
- silabs/gecko software development kit
- Source
- product-security@silabs.com
References
- https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U2sWXQAZ?operationContext=S1Permissions Required
- https://github.com/SiliconLabs/gecko_sdk/releasesRelease Notes
- https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U2sWXQAZ?operationContext=S1Permissions Required
- https://github.com/SiliconLabs/gecko_sdk/releasesRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.