TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-20017 | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.silabs.com/068Vm000001FrjT |
|
History
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Silabs
Silabs gecko Software Development Kit |
|
| CPEs | cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Silabs
Silabs gecko Software Development Kit |
Fri, 27 Sep 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-330 CWE-338 CWE-908 |
Fri, 27 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. | TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. |
| Weaknesses | CWE-1279 CWE-331 |
Status: PUBLISHED
Assigner: Silabs
Published:
Updated: 2024-09-27T16:06:44.910Z
Reserved: 2024-01-10T19:20:24.393Z
Link: CVE-2024-22473
Updated: 2024-08-01T22:51:09.859Z
Status : Analyzed
Published: 2024-02-21T19:15:08.813
Modified: 2025-02-12T16:52:42.397
Link: CVE-2024-22473
No data.
OpenCVE Enrichment
No data.
EUVD