CVE-2023-2747: Uninitialized IV in Silicon Labs SE FW v2.0.0 through v 2.2.1 for internally stored data
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2747?
CVE-2023-2747 is a vulnerability in the secure engine (SE) of Silabs Gecko Software Development Kit (SDK) that allows unauthorized access to encrypted data stored in the SE flash memory.
What is the severity of CVE-2023-2747?
CVE-2023-2747 has a severity rating of 5.5 (medium).
How does CVE-2023-2747 affect the Silabs Gecko Software Development Kit?
CVE-2023-2747 affects the Silabs Gecko Software Development Kit (SDK) versions 2.0.0 through 2.2.1.
How can I fix CVE-2023-2747?
To fix CVE-2023-2747, it is recommended to update the Silabs Gecko Software Development Kit (SDK) to a version that addresses the vulnerability.
Where can I find more information about CVE-2023-2747?
You can find more information about CVE-2023-2747 in the following references: 1. [CVE-2023-2747 Advisory by Silabs Community](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U2sFvQAJ?operationContext=S1) 2. [SiliconLabs/gecko_sdk GitHub repository](https://github.com/SiliconLabs/gecko_sdk)