CVE-2024-50928

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.
References
Link Resource
https://github.com/CNK2100/2024-CVE/blob/main/README.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:silabs:z-wave_software_development_kit:*:*:*:*:*:*:*:*
OR cpe:2.3:h:silabs:efr32zg14p231f256gm32:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b011f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b021f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm130s037hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sa27hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sb27hgn:-:*:*:*:*:*:*:*

History

01 Jul 2025, 15:32

Type Values Removed Values Added
First Time Silabs z-wave Software Development Kit
Silabs efr32zg23b010f512im48
Silabs efr32zg23a020f512gm40
Silabs efr32zg23b010f512im40
Silabs efr32zg23a010f512gm40
Silabs zgm230sa27hgn
Silabs efr32zg23b021f512im40
Silabs efr32zg23a010f512gm48
Silabs efr32zg23b020f512im40
Silabs zgm130s037hgn
Silabs efr32zg14p231f256gm32
Silabs efr32zg23a020f512gm48
Silabs efr32zg23b011f512im40
Silabs efr32zg23b020f512im48
Silabs zgm230sb27hgn
Silabs
CPE cpe:2.3:h:silabs:zgm230sb27hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b021f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a010f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23a020f512gm40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b020f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm230sa27hgn:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b010f512im48:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg14p231f256gm32:-:*:*:*:*:*:*:*
cpe:2.3:a:silabs:z-wave_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:h:silabs:efr32zg23b011f512im40:-:*:*:*:*:*:*:*
cpe:2.3:h:silabs:zgm130s037hgn:-:*:*:*:*:*:*:*
References () https://github.com/CNK2100/2024-CVE/blob/main/README.md - () https://github.com/CNK2100/2024-CVE/blob/main/README.md - Exploit, Third Party Advisory

12 Dec 2024, 02:06

Type Values Removed Values Added
Summary
  • (es) Los permisos inseguros en Silicon Labs (SiLabs) Z-Wave Series 700 y 800 v7.21.1 permiten a los atacantes cambiar el intervalo de activación de los dispositivos finales en la memoria del controlador, interrumpiendo las comunicaciones del dispositivo con el controlador.
CWE CWE-281
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 19:15

Updated : 2025-07-01 15:32


NVD link : CVE-2024-50928

Mitre link : CVE-2024-50928

CVE.ORG link : CVE-2024-50928


JSON object : View

Products Affected

silabs

  • efr32zg23a020f512gm40
  • efr32zg23b010f512im48
  • efr32zg23a010f512gm40
  • zgm230sa27hgn
  • efr32zg14p231f256gm32
  • efr32zg23b010f512im40
  • efr32zg23a010f512gm48
  • zgm130s037hgn
  • efr32zg23b021f512im40
  • efr32zg23b011f512im40
  • efr32zg23a020f512gm48
  • zgm230sb27hgn
  • efr32zg23b020f512im40
  • efr32zg23b020f512im48
  • z-wave_software_development_kit
CWE
CWE-281

Improper Preservation of Permissions