脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2
脆弱性説明
In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Groups cluster may be impacted.
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
脆弱性タイプ
跨界内存读
脆弱性タイトル
Silicon Labs EmberZNet 缓冲区错误漏洞
脆弱性説明
Silicon Labs EmberZNet是美国Silicon Labs公司的一个嵌入式无线网络协议栈软件。 Silicon Labs EmberZNet 9.0.2之前版本存在缓冲区错误漏洞,该漏洞源于畸形GetGroupMembership命令可触发对消息有效载荷末尾的重复读取并终止进程,可能导致仅支持Group集群的设备受影响。
CVSS情報
N/A
脆弱性タイプ
N/A