CVE-2023-4489CWE-1279

Z/IP Gateway Use of Uninitialized PRNG when Generating S0 Encryption Key

Medium · published December 14, 2023

CVSS v3.1
6.4
EPSS
1%
Percentile
42.6
In the wild
Unconfirmed
What it is

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0 network access.

The record
Technical detail
CVSS v3.1
6.4 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00525 · 42.6th percentile
Weakness
CWE-1279 · Cryptographic Operations are run Before Supporting Units are Ready
Published
2023-12-14T23:00Z
EPSS history
Timeline
  • 14 DEC 23:00Z
    Z/IP Gateway Use of Uninitialized PRNG when Generating S0 Encryption Key
    cvelistv5