CVE-2023-32097: Key duplication in GSDK
Published May 18, 2023
·Updated
Compiler removal of buffer clearing in
slicryptotransparentaeaddecrypttag
in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Affected Software
1 affected component
Silabs Gecko Software Development Kit<=4.2.1
Event History
May 18, 2023
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32097.
2
What is the severity of CVE-2023-32097?
CVE-2023-32097 has a severity rating of 7.5 (high).
3
How does the vulnerability in sli_crypto_transparent_aead_decrypt_tag occur?
The vulnerability in sli_crypto_transparent_aead_decrypt_tag occurs due to the compiler's removal of buffer clearing.
4
Which version of Silicon Labs Gecko Platform SDK is affected by CVE-2023-32097?
Silicon Labs Gecko Platform SDK v4.2.1 and earlier versions are affected by CVE-2023-32097.
5
What is the CWE number associated with CVE-2023-32097?
CVE-2023-32097 is associated with CWE-14 (Compiler Removal of Code to Clear Buffers).