A-00000512 Silicon Labs Security Advisory

2024-09-29 SILICON LABS


●主题:多协议环境中的拒绝服务-OpenThread边界路由器+Z3网关
●CVSS严重程度:中等
●受影响的产品
■受影响的商品汇总如下表所示:

▲基于EFR32的SoC和运行多协议RCP的相关模块
▲基于EFR33的SoC和执行多协议RCPs的相关模块
●CVE ID
■CVE-2024-017[1]已被保留用于此漏洞。

●技术摘要
■在多协议环境中,例如与Z3网关结合的OpenThread边界路由器(OTBR),OpenThread进程可能会被迫等待发送数据,直到Zigbee进程完成数据发送。在此期间,OpenThread进程的数据被缓冲。当通道空闲时,Thread数据会从缓冲区中解包,但用于解包数据的位置不正确。

■发生这种情况的一种可能方式是强制大量的Zigbee流量。这种类型的高流量可能是由大量Zigbee终端设备在短时间内加入网络而恶意造成的。这可能会导致拒绝服务(DOS)攻击。

■观察到的影响是,由于对损坏数据的错误处理不当,主机平台上运行的OTBR进程意外终止。

●修复/解决方法
■下载/更新GSDK或SiSDK[2]以及升级项目以使用新的GSDK或SixSDK版本[3]的说明可以在Simplicity Studio用户指南中找到
■以下SDK版本解决了该漏洞。始终建议客户升级到最新的SDK版本。

▲基于EFR32的SoC和运行多协议RCP的相关模块

世强先进(深圳)科技股份有限公司
世强硬创平台www.sekorm.com
世强硬创平台电子商城www.sekorm.com/supply/
世强硬创平台www.sekorm.com
世强硬创平台www.sekorm.com
- The full preview is over,the data is 2 pages -
Download Documentation will be sent to the business email and automatically synchronized to all devices for easy management
  • +1 Like
  • Add to Favorites

All reproduced articles on this site are for the purpose of conveying more information and clearly indicate the source. If media or individuals who do not want to be reproduced can contact us, which will be deleted.

Recommend

A-00000513 Silicon Labs Security Advisory

2024-JUN-27  - Development Environment(Software/Firmware)

A-00000511 Silicon Labs Security Advisory

2024-JUN-20  - Development Environment(Software/Firmware)

Silicon Labs Z-Wave Zniffer Software Release Note

2019-09-20  - Development Environment(Software/Firmware)

ZDB5202,400 SERIES,300 SERIES,500 SERIES

Silicon Labs Corporate Overview

FEBRUARY 2021  - Supplier and Product Introduction

查看更多版本

Radio Equipment Directive, Silicon Labs' Strategy, and more!

August 2025  - Technical Documentation

Dear Valued Silicon Labs Customer

2016/12/11  - Technical Documentation

UG392: Using Silicon Labs Green Power with Zigbee EmberZNet PRO

2025/01/01  - Application note & Design Guide

查看更多版本

QSG113: Getting Started with Silicon Labs Thread

2019/10/12  - User's Guide

EFR32MG12,EFR32MG

查看更多版本

Failure to update BT Mesh Replay Protection List vulnerability Silicon Labs Security Advisory

2024-JUN-06  - Development Environment(Software/Firmware)

Silicon Labs Z-Wave Security Advisory

Development Environment(Software/Firmware)

700 SERIES,500 SERIES

Silicon Labs Security Advisory A-00000506

2024-APR-11  - Development Environment(Software/Firmware)

WGM160P

AN1330: Silicon Labs Wi-SUN Mesh Network Performance

2023/1/27  - Application note & Design Guide

查看更多版本

UG495: Silicon Labs Wi-SUN Developer’s Guide

2023/12/6  - User's Guide

EFR32XG

查看更多版本
More

Electronic Mall

More

Manufacturer:ICLEGEND MICRO

Category:High Precision Multi-target Tracking mmWave Sensor

Auth. Dist.

Unit Price:$12.2710

Manufacturer:HSEC

Category:IoT Security Chip

Auth. Dist.

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:$220.0000

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:$26.2000

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:$130.0000

Manufacturer:MSKSEMI

Category:瞬态抑制二极管

Auth. Dist.

Unit Price:$0.0962

Manufacturer:Winner Micro

Category:SoC芯片

Auth. Dist.

Unit Price:$2.1774

Manufacturer:ELESY

Category:交流伺服电机

Auth. Dist.

Manufacturer:MSL

Category:存储器

Auth. Dist.

Manufacturer:thermal grizzly

Category:Thermal Paste

Auth. Dist.

In Stock:60

Manufacturer:ICLEGEND MICRO

Category:High Precision Multi-target Tracking mmWave Sensor

Auth. Dist.

Unit Price:

RFQ

Manufacturer:HSEC

Category:IoT Security Chip

Auth. Dist.
RFQ

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:

RFQ

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:

RFQ

Manufacturer:Terasilic

Category:24GHz Radar Front-End-Module

Auth. Dist.

Unit Price:

RFQ

Manufacturer:MSKSEMI

Category:瞬态抑制二极管

Auth. Dist.

Unit Price:

RFQ

Manufacturer:Winner Micro

Category:SoC芯片

Auth. Dist.

Unit Price:

RFQ

Manufacturer:ELESY

Category:交流伺服电机

Auth. Dist.
RFQ

Manufacturer:MSL

Category:存储器

Auth. Dist.
RFQ

Manufacturer:thermal grizzly

Category:Thermal Paste

Auth. Dist.

In Stock:

RFQ
connect

Contact Us

E-mail:contact@sekorm.com

Tel: +86 954668/400-830-1766