# Silicon Labs Security Advisory A-00000482 : Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices Flags: Zigbee, OpenThread CVSS Severity: High CVSS Base Score: 7.6, High CVSS Temporal Score: 7.3, High CVSS String: [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | OpenThread | 2.3.1 through 1.2.0 | GSDK | 4.3.1 through 3.2.0 | [CVE-2023-41095](https://nvd.nist.gov/vuln/detail/CVE-2023-41095), [CVE-2023-41096](https://nvd.nist.gov/vuln/detail/CVE-2023-41096) | | EmberZNet | 7.3.1 through 7.2.0 | GSDK | 4.3.1 through 4.2.0 | [CVE-2023-41095](https://nvd.nist.gov/vuln/detail/CVE-2023-41095), [CVE-2023-41096](https://nvd.nist.gov/vuln/detail/CVE-2023-41096) | ### Source Product Impact Details - Silabs Secure Vault High devices (SVH) running OpenThread 1.2.0 (GSDK 3.2.0) to 2.3.1 (GSDK 4.3.1) - Silabs SVH devices running Ember ZNet 7.2.0 (GSDK 4.2.0) to 7.3.1 (GSDK 4.3.1) - The OpenThread and Ember ZNet keys in Multiprotocol devices are affected by this vulnerability - Silicon Labs Matter devices are unaffected by this vulnerability ## Description - Silicon Labs’ implementation of OpenThread and Ember ZNet share code known as the “Security Manager” - When Wrapped key storage was initially introduced to Security Manager (in GSDK 3.2.0 for OpenThread and GSDK 4.2.0 for Ember ZNet) a bug in key importation led to keys not being stored in wrapped format as-expected - Rather than being stored in wrapped form, the keys continued to be stored in plaintext as they had in previous releases - For Silabs OpenThread stack, this vulnerability is tracked by [CVE-2023-41095](https://nvd.nist.gov/vuln/detail/CVE-2023-41095) - For Silabs Ember ZNet this vulnerability is tracked by [CVE-2023-41096](https://nvd.nist.gov/vuln/detail/CVE-2023-41096) - Due to underlying wear-leveling behavior in GSDK’s NVM driver, unwrapped keys may remain in flash even after updating firmware to an unaffected version, refer to Mitigating Potential Plaintext Key Remnants in NVM for mitigation steps ### Fix/Workaround - Affected OpenThread users should update to version 2.3.2 or later (GSDK 4.3.2 or later) - Affected Ember ZNet users should update to version 7.3.2 or later (GSDK 4.3.2 or later) - Instructions for [downloading/updating the GSDK](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar#install) and for [upgrading a project to use a new GSDK version](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version) can be found in the Simplicity Studio Users Guide #### Mitigating Potential Plaintext Key Remnants in NVM - To ensure plaintext keys remaining in NVM are not used, Ember ZNet customers using Zigbee Coordinator or Trust Center (TC) should roll network keys after updating affected firmware using the following steps: 1. Enable the trust-center-nwk-key-update-periodic plugin paired with either trust-center-nwk-key- update-broadcast or trust-center-nwk-key-update-unicast plugins via Simplicity Studio Application Framework to send new key notifications from an affected TC 2. Update the firmware on all affected end-nodes 3. Rebuild the TC firmware with trust-center-nwk-key-update-periodic enabled and a suitable update policy selected 4. Ensure at least one periodic network key update interval passes - Ember ZNet customers not using a Zigbee Coordinator or Trust Center should factory reset all affected devices applying a firmware update and recommission using new network keys - To ensure plaintext keys remaining in NVM are not used, OpenThread networks should update to version 2.3.2 or later before forcing a pending/active dataset change via commissioner or using the dataset manager feature in OpenThread using the following steps: 1. Have a Full Thread Device on the network start a commissioner role, this can be initiated by the following CLI command on Silabs OpenThread devices: 2. Check the existing network key in your active dataset 3. Force a network key change as commissioner by sending a pending dataset using a new network key ## Certification Impact - While there is no key storage requirement for OpenThread Certification, updating to newer releases of an OpenThread Stack may require recertification. [Contact the Thread Group](help@threadgroup.org) for more information on certification requirements. - While there is no key storage requirement for Zigbee Certification, updating to newer releases of a Zigbee stack may require recertification. [Contact the Connectivity Standards Alliance](help@csa-iot.org) for more information on recertification requirements. ## Revision History | Version | Date | Description of Changes | | --- | --- | --- | | 3.0 | 2024-JAN-18 | Added information about persistent plaintext network keys in NVM | | | | Added mitigation steps to remove potential plaintext network keys from NVM | | 2.0 | 2023-OCT-20 | Updated vector string to denote Scope:Changed | | | | Updated CVSS Base and Temporal Scores | | 1.0 | 2023-OCT-19 | Initial publication | ## Attribution ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)