The following APIs for the Silcon Labs SiWx91x prior to vesion 3.4.0 failed to check the size of the output buffer of the caller which could lead to data corruption on the host (Cortex-M4) application.


sl_si91x_aes
sl_si91x_gcm
sl_si91x_ccm
sl_si91x_sha
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 26 Jul 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
Description The following APIs for the Silcon Labs SiWx91x prior to vesion 3.4.0 failed to check the size of the output buffer of the caller which could lead to data corruption on the host (Cortex-M4) application. sl_si91x_aes sl_si91x_gcm sl_si91x_ccm sl_si91x_sha
Title Buffer overflow in Si91x crypto APIs
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2025-07-25T18:32:06.955Z

Reserved: 2025-04-22T15:48:02.536Z

Link: CVE-2025-3873

cve-icon Vulnrichment

Updated: 2025-07-25T18:32:02.557Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-25T16:15:33.560

Modified: 2025-07-29T14:14:55.157

Link: CVE-2025-3873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.