A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
CVE ID: CVE-2023-0971
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.6
Vendor: Silicon Labs
Product: Z/IP Gateway
EPSS Score: 0.07% (probability of being exploited)
EPSS Percentile: 33.63% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)