Dos in ZigBee device due to unsolicited encrypted rejoin response
Summary
| CVE | CVE-2024-7322 |
|---|---|
| State | PUBLISHED |
| Assigner | Silabs |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-01-15 08:15:26 UTC |
| Updated | 2026-04-20 16:16:39 UTC |
| Description | A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established |
Risk And Classification
Primary CVSS: v3.1 5.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
EPSS: 0.001170000 probability, percentile 0.302950000 (date 2026-04-21)
Problem Types: CWE-940 | CWE-940 CWE-940 Improper Verification of Source of a Communication Channel
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 5.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Silabs.com | EmberZNet | affected 7.3.3 semver | Not specified |
| CNA | Silabs.com | EmberZNet | affected 7.4.0 7.4.4 semver | Not specified |
| CNA | Silabs.com | EmberZNet | affected 8.1.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| community.silabs.com/068Vm00000I7ri2 | [email protected] | community.silabs.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.