CVE-2024-22473

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
References
Link Resource
https://community.silabs.com/068Vm000001FrjT Permissions Required
https://community.silabs.com/068Vm000001FrjT Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*

History

12 Feb 2025, 16:52

Type Values Removed Values Added
References () https://community.silabs.com/068Vm000001FrjT - () https://community.silabs.com/068Vm000001FrjT - Permissions Required
CPE cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*
First Time Silabs
Silabs gecko Software Development Kit

21 Nov 2024, 08:56

Type Values Removed Values Added
References () https://community.silabs.com/068Vm000001FrjT - () https://community.silabs.com/068Vm000001FrjT -

27 Sep 2024, 17:15

Type Values Removed Values Added
CWE CWE-330
CWE-908
CWE-338
CWE-331
CWE-1279
Summary (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

22 Feb 2024, 19:07

Type Values Removed Values Added
Summary
  • (es) TRNG se utiliza antes de la inicialización mediante el controlador de firma ECDSA al salir de EM2/EM3 en dispositivos Virtual Secure Vault (VSE). Este defecto puede permitir la suplantación de firmas mediante recreación clave. Este problema afecta a Gecko SDK hasta la versión 4.4.0.

21 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 19:15

Updated : 2025-02-12 16:52


NVD link : CVE-2024-22473

Mitre link : CVE-2024-22473

CVE.ORG link : CVE-2024-22473


JSON object : View

Products Affected

silabs

  • gecko_software_development_kit
CWE
CWE-331

Insufficient Entropy

CWE-1279

Cryptographic Operations are run Before Supporting Units are Ready