CVE-2024-22473

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
References
Link Resource
https://community.silabs.com/068Vm000001FrjT Permissions Required
https://community.silabs.com/068Vm000001FrjT Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*

History

12 Feb 2025, 16:52

Type Values Removed Values Added
References () https://community.silabs.com/068Vm000001FrjT - () https://community.silabs.com/068Vm000001FrjT - Permissions Required
First Time Silabs
Silabs gecko Software Development Kit
CPE cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*

21 Nov 2024, 08:56

Type Values Removed Values Added
References () https://community.silabs.com/068Vm000001FrjT - () https://community.silabs.com/068Vm000001FrjT -

27 Sep 2024, 17:15

Type Values Removed Values Added
Summary (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
CWE CWE-908
CWE-338
CWE-330
CWE-1279
CWE-331

21 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 19:15

Updated : 2025-02-12 16:52


NVD link : CVE-2024-22473

Mitre link : CVE-2024-22473

CVE.ORG link : CVE-2024-22473


JSON object : View

Products Affected

silabs

  • gecko_software_development_kit
CWE
CWE-331

Insufficient Entropy

CWE-1279

Cryptographic Operations are run Before Supporting Units are Ready