Back to overview

CVE-2026-47154

HIGH
7.1
CVSS 4.0
Description
In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.

Metadata

CVE ID
CVE-2026-47154
State
PUBLISHED
Assigner
Silabs
Reserved
2026-05-18 20:02 UTC
Published
2026-06-25 13:43 UTC
Last updated
2026-06-25 14:19 UTC
Primary CWE
CWE-125
CWE-125: Out-of-bounds Read
Vendor / Product
Silicon Labs / EmberZNet
Sources
cve.org  ·  NVD

Severity & Metrics

7.1 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Silicon Labs EmberZNet 0 ≤ 9.0.2
Weakness (CWE)
CWESourceDescription
CWE-125 cna CWE-125: Out-of-bounds Read
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.1 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Back to overview