Vulnerability Description
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silabs | Gecko Software Development Kit | <= 4.4.0 |
Related Weaknesses (CWE)
References
- https://community.silabs.com/068Vm000001FrjTPermissions Required
- https://community.silabs.com/068Vm000001FrjTPermissions Required
FAQ
What is CVE-2024-22473?
CVE-2024-22473 is a vulnerability with a CVSS score of 6.8 (MEDIUM). TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gec...
How severe is CVE-2024-22473?
CVE-2024-22473 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22473?
Check the references section above for vendor advisories and patch information. Affected products include: Silabs Gecko Software Development Kit.