# Silicon Labs Security Advisory A-00000463 : OpenThread Vulnerability - Key ID Mode 2 Security Flags: OpenThread, Matter CVSS Severity: High CVSS Base Score: 8.0, High CVSS Temporal Score: 7.4, High CVSS String: [CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | OpenThread | 2.2.2 and earlier | GSDK | 4.2.2 and earlier | - | | Silicon Labs Matter GitHub | 2.1.0-1.1 and earlier | GSDK | 4.3.1 and earlier | - | ### Source Product Impact Details - All Silicon Labs OpenThread devices released before GSDK 4.2.3 - Silicon Labs Matter [1] released before 2.1.0-1.1 - Silicon Labs Open Thread for EFR32 (ot-efr32) devices prior to commit 6f56062 [2] ## Description - Thread uses Fixed-Source keying (MAC Key ID Mode 2) for certain messages. The key used in this mode is pre-defined and openly specified. As a result the Thread specification mandates additional processing for these messages. However, a defect in OpenThread omits the specified extra processing, potentially allowing adjacent devices to inject IPv6 packets through a routing-capable device. - A potential attacker may be able to use this vulnerability to update the Thread Network Key and potentially gain full access to the Thread network - Any Thread network with a router or router-capable device with this vulnerability is impacted - Thread end devices (i.e. non-router-capable devices) with this vulnerability are impacted, but attacks are limited to the end device itself - End devices with application layer security (Matter, HomeKit, etc.) should not be affected with regard to integrity and confidentiality, however availability may still be impacted by prevented delivery of Thread messages - This vulnerability has not been detected in use by malicious actors ### Fix/Workaround - Impacted GSDK users should update to version 4.2.3 or later 1. Under Simplicity Studio 5, navigate to the Installation Manager by clicking or by navigating to “Help” > “Update Software,” 2. Under the Installation Manager, select “Manage Installed Packages” > “SDKs” and install Gecko SDK 4.2.3 or greater, then clean and rebuild your project - Impacted Silabs Matter users should update to release 2.1.0-1.1 1. Update all tags in your local copy of the Silicon Labs Matter Github repository git fetch --all --tags 2. Under a local branch of the Silicon Labs Matter Github repository, check out tag 2.1.0-1.1 git checkout 2.1.0-1.1 3. Clean and rebuild your project following the Silicon Labs Matter Developer Reference [3] for your specific use case - Silab’s Open Thread for EFR32 [4] Github repository (ot-efr32) will be updated to point to the official fix when it becomes available on the official Open Thread [5] Github repository ## Certification Impact - All Thread Certified products using OpenThread are required to mitigate this defect by June 16 th 2023. Additionally, ALL Thread Certified products must be re-certified - For more information regarding Thread re-certificatio, contact The Thread Group, Inc. [6]. - For more information regarding re-certification, contact CSA [7]. ## Attribution - This vulnerability was discovered by external Security Researchers and forwarded to Thread Group members under security embargo on April 27th, 2023 [1] [https://github.com/SiliconLabs/matter](https://github.com/SiliconLabs/matter) [2] [https://github.com/openthread/ot-efr32/commit/6f56062fd8f53f6b3d6e361e97a9aa20c271dafc](https://github.com/openthread/ot-efr32/commit/6f56062fd8f53f6b3d6e361e97a9aa20c271dafc) [3] [https://siliconlabs.github.io/matter/2.1.0-1.1/nav_3_general.html](https://siliconlabs.github.io/matter/2.1.0-1.1/nav_3_general.html) [4] [https://github.com/openthread/ot-efr32](https://github.com/openthread/ot-efr32) [5] [https://github.com/openthread/openthread](https://github.com/openthread/openthread) [6] [https://www.threadgroup.org/contact](https://www.threadgroup.org/contact) [7] [https://csa-iot.org/contact-us/](https://csa-iot.org/contact-us/) ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.0 | 2023-JUL-05 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)