First published: Thu May 18 2023(Updated: )
Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-32098.
The severity of CVE-2023-32098 is high with a CVSS score of 7.5.
The Silicon Labs Gecko Platform SDK versions up to and including 4.2.1 is affected by this vulnerability.
The vulnerability results in key material duplication to RAM.
To fix the vulnerability, it is recommended to update to a version later than 4.2.1 of Silicon Labs Gecko Platform SDK.