This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the debug interface. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-21367 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.
Fixes

Solution

Silicon Labs has issued an update to correct this vulnerability. More details can be found at: https://community.silabs.com/a45Vm0000000Atp


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00038}


Tue, 01 Jul 2025 02:30:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 19 Jun 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Silabs
Silabs gecko Os
CPEs cpe:2.3:o:silabs:gecko_os:*:*:*:*:*:*:*:*
Vendors & Products Silabs
Silabs gecko Os

Fri, 14 Mar 2025 06:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 19 Feb 2025 04:45:00 +0900

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Sat, 01 Feb 2025 02:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 09:15:00 +0900

Type Values Removed Values Added
Description This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.
Title Silicon Labs Gecko OS Debug Interface Format String
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-07-01T13:40:42.425Z

Reserved: 2024-01-23T21:45:30.919Z

Link: CVE-2024-23937

cve-icon Vulnrichment

Updated: 2025-01-31T16:54:24.614Z

cve-icon NVD

Status : Modified

Published: 2025-01-31T00:15:09.257

Modified: 2025-07-01T14:15:32.250

Link: CVE-2024-23937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses