CVE-2023-4489
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.69%
- CWE
- CWE-1279
- Published
- 2023-12-14
- Last modified
- 2026-03-13
Affected products
- silabs.com Z/IP Gateway SDK
Weakness type
Related vulnerabilities
- CVE-2025-29779 — Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
- CVE-2024-22473 — Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices