CVE-2026-6924
Received Received - Intake

SiWx917 DRBG Predictable Seed in Matter Code

Vulnerability report for CVE-2026-6924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-24

Assigner: Silicon Graphics (SGI)

Description

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-24
Generated
2026-08-13
AI Q&A
2026-07-24
EPSS Evaluated
2026-08-11
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
silicon_labs siwx917 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-336 A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a bug in the entropy initialization for the SiWx917 device, causing the Deterministic Random Bit Generator (DRBG) to use a predictable seed. As a result, all random numbers generated in the Matter code use the same predictable sequence of numbers.

Detection Guidance

This vulnerability involves a predictable seed in the DRBG of SiWx917, leading to non-random number generation in Matter code. Detection requires checking for non-random outputs in cryptographic operations or logs indicating entropy initialization failures. No specific commands are provided in the context.

Impact Analysis

This vulnerability can lead to security risks such as compromised encryption keys, session tokens, or other sensitive data generated using the predictable random numbers. It undermines cryptographic operations and could allow attackers to predict or manipulate system behavior.

Compliance Impact

This vulnerability could potentially impact compliance with standards requiring secure random number generation, such as cryptographic operations in GDPR or HIPAA. Predictable random numbers may weaken encryption, leading to unauthorized data access or integrity issues.

Mitigation Strategies

Since the affected repository is already deprecated and the vulnerability stems from a predictable seed in the DRBG, no direct mitigation commands are provided. Consider replacing or updating the SiWx917 device firmware if available, or migrate away from the deprecated repository to avoid potential risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart