CVE-2026-6924CWE-336

Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path

High · published July 23, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
37.3
In the wild
Unconfirmed
What it is

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00445 · 37.3th percentile
Weakness
CWE-336 · Same Seed in Pseudo-Random Number Generator (PRNG)
Published
2026-07-23T21:05Z
EPSS history
Timeline
  • 23 JUL 21:05Z
    Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
    cvelistv5