Description
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
Published: 2023-12-21
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-45617 An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-385

Wed, 25 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0. An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
Weaknesses CWE-327

Subscriptions

Silabs Gecko Software Development Kit
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2025-04-23T16:23:05.829Z

Reserved: 2023-08-23T04:17:16.169Z

Link: CVE-2023-41097

cve-icon Vulnrichment

Updated: 2024-08-02T18:46:11.874Z

cve-icon NVD

Status : Modified

Published: 2023-12-21T21:15:08.020

Modified: 2024-11-21T08:20:34.237

Link: CVE-2023-41097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses