CVE-2023-32096: Key duplication in GSDK
Compiler removal of buffer clearing in
slicryptotransparentaeadencrypttag
in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-32096.
What is the title of this vulnerability?
The title of this vulnerability is 'Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.'
What is the severity level of CVE-2023-32096?
The severity level of CVE-2023-32096 is high, with a CVSS score of 7.5.
How does this vulnerability affect the affected software?
This vulnerability affects Silicon Labs Gecko Platform SDK v4.2.1 and earlier, and it results in key material duplication to RAM.
Are there any references for more information about this vulnerability?
Yes, you can find more information about this vulnerability at the following references: [reference 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000U19lGQAR?operationContext=S1), [reference 2](https://github.com/SiliconLabs/gecko_sdk).