Command Authentication Bypass in Z/IP Gateway
CVE-2023-0971
9.6CRITICAL
What is CVE-2023-0971?
A logic error in SiLabs Z/IP Gateway SDK versions 7.18.02 and earlier enables an attacker to bypass authentication mechanisms. This vulnerability allows for unauthorized remote administration of Z-Wave controllers and exposes sensitive S0/S2 encryption keys. If exploited, it poses significant risks to the security of devices utilizing Z-Wave communications, threatening the integrity and confidentiality of managed systems. Immediate actions are recommended to mitigate potential exploitation of this vulnerability.
Affected Version(s)
Z/IP Gateway 7.18.03