ZeroHour

CVE-2024-22473

CVSS 3.1
7.5 high
EPSS
<1%p33
Published
()
Modified
Description

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

Vendors
silabs
Products
gecko software development kit
Weakness
CWE-331, CWE-1279
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.