<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ember (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/emberjs.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/emberjs-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ember (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2023-6874 – Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6874</guid>
    <pubDate>Mon, 05 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6874</strong></p>
  <p>Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41094 – TouchLink packets processed after timeout or out of range due to Operation on a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41094</guid>
    <pubDate>Wed, 04 Oct 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41094</strong></p>
  <p>TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration  This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41094">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
