CVE-2023-3488: Uninitialized variable in Gecko Bootloader can leak secure stack
Published Jul 28, 2023
·Updated
Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
Affected Software
1 affected component
Silabs Gecko Software Development Kit<=4.3.0
Event History
Jul 28, 2023
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-3488?
The severity of CVE-2023-3488 is medium.
2
What is the affected software for CVE-2023-3488?
The affected software for CVE-2023-3488 is Silicon Labs GSDK v4.3.0 and earlier.
3
How can an attacker exploit CVE-2023-3488?
An attacker can exploit CVE-2023-3488 by using a malformed GBL file to leak data from the Secure stack.
4
Is there a fix available for CVE-2023-3488?
Yes, updating to Silicon Labs GSDK version 4.3.1 or later fixes CVE-2023-3488.
5
Where can I find more information about CVE-2023-3488?
More information about CVE-2023-3488 can be found in the references provided: [Link 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000Wi3HwQAJ?operationContext=S1), [Link 2](https://github.com/SiliconLabs/gecko_sdk/releases).