Buffer Overread Vulnerability in CPC Application by Silicon Labs
CVE-2024-12975
1LOW
What is CVE-2024-12975?
A buffer overread vulnerability exists in the CPC application developed by Silicon Labs. This issue manifests when the application operates in full duplex SPI mode and attempts to process an invalid packet received over the SPI interface. This condition can lead to unexpected data exposure, making the system susceptible to potential security risks. It is crucial for users to implement the recommended patches and updates to mitigate this vulnerability effectively.
Affected Version(s)
Simplicity SDK 0 < 2024.12.1
References
CVSS V4
Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
