CVE-2023-28391: Silabs Gecko Software Development Kit
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
Affected products
- Silabs Gecko Software Development Kit: version 4.3.1 only
- Weston-Embedded Cesium Net: version 3.07.01 only
- Weston-Embedded Uc-HTTP: version 3.01.01 only
Published 2023-11-14. Last modified 2026-06-17.