HomeSilabsCVE-2024-22473

CVE-2024-22473

MEDIUM
6.8CVSS
Published: 2024-02-21
Updated: 2025-02-12
AI Analysis

Description

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
changed
Confidentiality
none
Integrity
high
Availability
none
Weaknesses
CWE-331CWE-1279CWE-331

Metadata

Primary Vendor
SILABS
Published
2/21/2024
Last Modified
2/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

silabs : gecko_software_development_kit

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-22473 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com