CVE-2026-6924
Received Received - Intake

SiWx917 DRBG Predictable Seed in Matter Code

Vulnerability report for CVE-2026-6924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Silicon Graphics (SGI)

Description

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
silicon_labs siwx917 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-336 A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a bug in the entropy initialization for the SiWx917 device, causing the Deterministic Random Bit Generator (DRBG) to use a predictable seed. As a result, all random numbers generated in the Matter code use the same predictable sequence of numbers.

Impact Analysis

This vulnerability can lead to security risks such as compromised encryption keys, session tokens, or other sensitive data generated using the predictable random numbers. It undermines cryptographic operations and could allow attackers to predict or manipulate system behavior.

Mitigation Strategies

Since the affected repository is already deprecated and the vulnerability stems from a predictable seed in the DRBG, no direct mitigation commands are provided. Consider replacing or updating the SiWx917 device firmware if available, or migrate away from the deprecated repository to avoid potential risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart