CVE-2023-2481: Key duplication in GSDK
Published May 18, 2023
·Updated
Compiler removal of buffer clearing in
sliseopaqueimportkey
in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Affected Software
1 affected component
Silabs Gecko Software Development Kit<=4.2.1
Event History
May 18, 2023
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-2481.
2
What is the severity of CVE-2023-2481?
The severity of CVE-2023-2481 is high.
3
How does the vulnerability occur?
The vulnerability occurs due to the compiler removing buffer clearing in sli_se_opaque_import_key function in Silicon Labs Gecko Platform SDK v4.2.1 and earlier.
4
What is the impact of the vulnerability?
The impact of the vulnerability is key material duplication to RAM.
5
How can I fix this vulnerability?
To fix this vulnerability, update to a version of Silicon Labs Gecko Platform SDK that is later than v4.2.1.