CVE-2026-6924
Received
Received - Intake
SiWx917 DRBG Predictable Seed in Matter Code
Vulnerability report for CVE-2026-6924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-23
Last updated on: 2026-07-23
Assigner: Silicon Graphics (SGI)
Description
Description
A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| silicon_labs | siwx917 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-336 | A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized. |