Use of Uninitialized Resource Affecting SiliconLabs/simplicity_sdk package, versions [,2024.12.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SILICONLABSSIMPLICITYSDK-12027895
  • published20 Aug 2025
  • disclosed25 Jul 2025
  • creditUnknown

Introduced: 25 Jul 2025

NewCVE-2025-2329  (opens in a new tab)
CWE-908  (opens in a new tab)

How to fix?

Upgrade SiliconLabs/simplicity_sdk to version 2024.12.3 or higher.

Overview

Affected versions of this package are vulnerable to Use of Uninitialized Resource via invalid SPI headers. An attacker can cause the device to send corrupt packets to its host by generating high traffic, which may result in the host resetting RCP and disrupting normal operation.

CVSS Base Scores

version 4.0
version 3.1