CVE-2024-50924

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.
References
Link Resource
https://github.com/CNK2100/2024-CVE/blob/main/README.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:silabs:z-wave_software_development_kit:*:*:*:*:*:*:*:*
OR cpe:2.3:h:silabs:efr32zg14p231f256gm32:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b011f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b021f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm130s037hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sa27hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sb27hgn:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-10 19:15

Updated : 2025-07-01 15:28


NVD link : CVE-2024-50924

Mitre link : CVE-2024-50924

CVE.ORG link : CVE-2024-50924


JSON object : View

Products Affected

silabs

  • zgm230sb27hgn
  • zgm230sa27hgn
  • efr32zg23b010f512im40
  • efr32zg23a020f512gm40
  • zgm130s037hgn
  • efr32zg23b010f512im48
  • efr32zg23b020f512im40
  • efr32zg23b021f512im40
  • efr32zg23a010f512gm40
  • efr32zg23b020f512im48
  • efr32zg23b011f512im40
  • z-wave_software_development_kit
  • efr32zg14p231f256gm32
  • efr32zg23a010f512gm48
  • efr32zg23a020f512gm48
CWE
CWE-281

Improper Preservation of Permissions