CVE-2024-8361
In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device will restart after watch dog expires. If watchdog is not implemented, device can be recovered only after a hard reset
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.43%
- CWE
- CWE-131, CWE-617
- Published
- 2025-01-07
- Last modified
- 2026-03-13
Affected products
- silabs.com WiSeConnect SDK
Weakness type
Related vulnerabilities
- CVE-2023-36824 — Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
- CVE-2024-23622 — IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
- CVE-2024-23621 — IBM Merge Healthcare eFilm Workstation License Server Buffer Overflow
- CVE-2021-0254 — Junos OS: Remote code execution vulnerability in overlayd service
- CVE-2020-13585 — An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A spe
- CVE-2023-24819 — RIOT-OS vulnerable to Buffer Overflow during IPHC receive
- CVE-2022-22137 — A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci
- CVE-2021-21793 — An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear