CVE-2026-6924CWE-336
Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
High · published July 23, 2026
What it is
A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
The record
Technical detail
- CVSS v4.0
- 8.7 · HIGH
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00445 · 37.3th percentile
- Weakness
- CWE-336 · Same Seed in Pseudo-Random Number Generator (PRNG)
- Published
- 2026-07-23T21:05Z
EPSS history
Timeline