Silicon Labs
  • ⟵ Back
    Products
    On-Demand
    Experience every keynote, fireside chat, and technical IoT training session from this year’s premier IoT conference
    WirelessWireless
    Amazon Sidewalk
    Bluetooth
    LPWAN
    Matter
    Multiprotocol
    Proprietary
    Thread
    Wi-Fi
    Wi-SUN
    Z-Wave
    Zigbee
    Non-WirelessNon-Wireless
    MCUs
    Power Management
    Sensors
    USB Bridges
    IoT TechnologiesIoT Technologies
    Channel Sounding
    Energy Harvesting
    Machine Learning
    Security
    ServicesServices
    Custom Part Manufacturing
    Developer Services
    SDK Extended Maintenance Service
  • ⟵ Back
    Applications
    Smart HomeSmart Home
    Appliances
    Connected Outdoor
    Entertainment Devices
    IoT Gateways
    LED Lighting
    Security Cameras
    Sensors
    Smart Locks
    Switches
    Industrial IoTIndustrial IoT
    Access Control
    Asset Tracking
    Battery-Powered Tools
    Circuit Breakers
    Commercial Lighting
    Electric Submetering
    Emergency Lighting
    Factory Automation
    Human Machine Interface
    Industrial Wearables
    Predictive Maintenance
    Process Automation
    Smart HVAC
    Smart CitiesSmart Cities
    Battery Storage
    EV Charging Stations
    Smart Agriculture
    Smart Buildings
    Smart Metering
    Smart Solar PV System
    Street Lighting
    Smart RetailSmart Retail
    Commercial Lighting
    Direction Finding
    Electronic Shelf Labels
    Loss Prevention
    Wi-Fi Access Points
    Connected HealthConnected Health
    Portable Medical Devices
    Smart Hospitals
    Smart Wearable Devices
  • ⟵ Back
    Software & Tools
    Simplicity Studio 6
    Fast track IoT development
    Software & ToolsSoftware & Tools
    Simplicity AI SDK
    Software Development Kits (SDKs)
    SDK Release Notes
    Software Reference Documentation
    Software Development Tools
    Hardware Development Tools
    Hardware Documentation
    GitHub Resources
    Developer JourneysDeveloper Journeys
    AI/ML
    Amazon Sidewalk
    Bluetooth
    Bluetooth Mesh
    Google Home
    Matter
    Wi-Fi
    ServicesServices
    Custom Part Manufacturing
    Developer Services
    SDK Extended Maintenance Service
  • ⟵ Back
    Resources
    DocumentationDocumentation
    Blog
    Case Studies
    Software Documentation
    Technical Library
    Whitepapers
    TrainingTraining
    Works With On-Demand 2025
    Tech Talks 2025 On-Demand
    Webinars
    Curriculum
    PartnersPartners
    Channel & Distribution
    Ecosystem Partners
    Partner Network
    ServicesServices
    Custom Part Manufacturing
    Developer Services
    SDK Extended Maintenance Service
    SupportSupport
    Community
    Submit a Ticket
    Quality and Packaging
    How to Buy
    Report a Security Issue
    Contact Us
  • ⟵ Back
    Company
    About our CompanyAbout our Company
    Community Commitment
    Inclusion at Silicon Labs
    Management Team
    Security
    SustainabilitySustainability
    Environmental, Social & Governance
    Quality
    Supply Chain Responsibility
    News & EventsNews & Events
    Blog
    News Room
    Events
    Investor RelationsInvestor Relations
    Annual Report & Proxies
    Board of Directors
    Corporate Governance
    Quarterly Results
    SEC Filings
    CareersCareers
    Hyderabad Office
    Other Global Offices
    Contact Us
English
  • English
  • 简体中文
  • 日本語
Ask AI
AskAI
Ask AI
//
Security // Security Vulnerability FAQs

Security Vulnerability FAQs

At Silicon Labs, we are committed to working collaboratively with the security research community, customers, and partners to identify and address vulnerabilities in a responsible and timely manner. As a CVE Numbering Authority (CNA), Silicon Labs follows industry practices for vulnerability disclosure and management, ensuring transparency and accountability throughout the process.

This FAQ page is designed to provide clear guidance on how to report potential security issues, what to expect during the disclosure process, and how we handle vulnerability disclosures. Whether you're a researcher, developer, or customer, we appreciate your efforts in helping us maintain a secure ecosystem. 

Reporting Vulnerabilities

To report a product security vulnerability, please register and create an account at community.silabs.com and click on the "Vulnerability Disclosure" tab on the top right-hand corner to select the "Vulnerability Report Submission" option in the drop-down menu. Alternately, you can also email our PSIRT at product-security@silabs.com. Please include a detailed description of the vulnerability, steps to reproduce it, and any supporting materials (e.g., proof-of-concept code) with every submission. For secure communication, use our PSIRT PGP Key. We encourage responsible disclosure and will acknowledge your submission within 3 business days. 

To report an enterprise asset security vulnerability, please register and create an account at community.silabs.com and click on the "Vulnerability Disclosure" tab on the top right-hand corner to select the "Vulnerability Report Submission" option in the drop-down menu. Alternately, you can also email our ESIRT at DL.Enterprise_Security@silabs.com. Please do not send an email to our PSIRT, as that is a channel specific to product security vulnerabilities. We encourage responsible disclosure and will acknowledge your submission within 3 business days. 

Please provide: 

  • A clear description of the vulnerability. 
  • Affected product(s) and version(s). 
  • Steps to reproduce the issue. 
  • Potential impact (e.g., data breach, system compromise). 
  • Any proof-of-concept code or screenshots (if applicable). 
  • Your contact information for follow-up. 
  • Attribution details, if attribution is preferred.
  • For coding vulnerabilities, please point to the exact location of the vulnerable files

This helps our PSIRT assess and address the issue quickly.

Yes, we accept anonymous submissions. However, providing contact information allows us to follow up for clarification and, if applicable, discuss eligibility for our Bug Bounty Program, which is coming up in early 2026.  



Disclosure Process

Disclosure: We publish a security advisory to notify subscribed users of the vulnerability. To learn how to sign up for security advisory notifications, click here. 

Yes, we adhere to coordinated vulnerability disclosure principles. We work with reporters to validate and remediate vulnerabilities before public disclosure, minimizing risk to our customers. We aim to publish security advisories alongside available fixes. In certain cases, a fix may not be released.  

Once a security advisory is released by Silicon Labs, the advisory cannot be distributed through message boards, social media, direct messaging, or other informal channels. However, researchers are welcome to reference the published CVEs in their communications or publications.   

You can view previously published security advisories in our Community portal (you need to be logged in). You can filter security advisories based on product categories. More details on this topic can be found here.

You can sign up for email notifications when a new Security Advisory is published here. You will receive access to all security advisories published, but will only receive notifications when a new advisory is published based on the product categories you select when subscribing to notifications. 



Bug Bounty Program

Coming Soon in 2026



General Questions

Our Product Security Incident Response Team (PSIRT) manages the identification, assessment, and resolution of security vulnerabilities in our products. We coordinate with researchers, customers, and partners to ensure timely fixes and transparent communication. 

We prioritize fixes using a combination of industry standards and internal assessments. We utilize the Common Vulnerability Scoring System (CVSS) 4.0, which enables us to assess the severity of each issue. Critical vulnerabilities receive the highest priority, and we aim to disclose and resolve them within 90 days.

Yes, we are a CNA (CVE Numbering Authority). This enables us to assign CVEs to confirmed vulnerabilities when appropriate, facilitating the public disclosure of security issues. We include relevant CVE numbers in each security advisory. 

We take data privacy seriously. Reports are handled confidentially, stored securely, and shared only with team members involved in resolution. Use our PSIRT PGP Key for encrypted submissions. See our Security Vulnerability Disclosure Policy and Privacy Notice for details. 

Silicon Labs

Stay Connected With Us

Plug into the latest on Silicon Labs products, including product releases and resources, documentation updates, PCN notification, upcoming events, and more.

  • About Us
  • Careers
  • Community
  • Contact Us
  • Corporate Responsibility
  • Investor Relations
  • Press Room
  • Privacy and Terms
  • Site Feedback

Connect With Us:

Silicon Labs
Also of Interest:
  • Quality, Environmental, Supply Chain, and...
  • Report a Security Vulnerability
  • With an Eye on Security, CSA Releases the...
Copyright Silicon Laboratories. All rights reserved.

Your File Will Start Downloading Shortly

Thank you for downloading .

If you have any issues downloading, please contact sales support or product technical support.

Close
Loading Results
Close

Please select at least one column.