Improper Resource Shutdown or Release Affecting SiliconLabs/gecko_sdk package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SILICONLABSGECKOSDK-7242921
  • published11 Jun 2024
  • disclosed6 Jun 2024
  • creditUnknown

Introduced: 6 Jun 2024

CVE-2024-4013  (opens in a new tab)
CWE-404  (opens in a new tab)

How to fix?

There is no fixed version for SiliconLabs/gecko_sdk.

Overview

Affected versions of this package are vulnerable to Improper Resource Shutdown or Release due to the mesh_node_power_off API. An attacker can replay unsaved messages by exploiting the failure to copy the Replay Protection List from RAM to NVM before the system powers down.

Note:

As of June 2024, the Gecko SDK was renamed to Simplicity SDK, and the versioning scheme was changed from Gecko SDK vX.Y.Z to Simplicity SDK YYYY.MM.Patch#. To fix this vulnerability, update to Simplicity SDK v2024.6.0.

CVSS Scores

version 3.1