CVE-2024-22473

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
References
Link Resource
https://community.silabs.com/068Vm000001FrjT Permissions Required
https://community.silabs.com/068Vm000001FrjT Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*

History

12 Feb 2025, 16:52

Type Values Removed Values Added
CPE cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Silabs gecko Software Development Kit
Silabs
CWE CWE-331
References () https://community.silabs.com/068Vm000001FrjT - () https://community.silabs.com/068Vm000001FrjT - Permissions Required

27 Sep 2024, 17:15

Type Values Removed Values Added
Summary TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

21 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 19:15

Updated : 2025-02-12 16:52


NVD link : CVE-2024-22473

Mitre link : CVE-2024-22473


JSON object : View

Products Affected

silabs

  • gecko_software_development_kit
CWE
CWE-331

Insufficient Entropy