First published: Fri Jul 28 2023(Updated: )
Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
Credit: product-security@silabs.com product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Gecko Software Development Kit | <=4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3488 is medium.
The affected software for CVE-2023-3488 is Silicon Labs GSDK v4.3.0 and earlier.
An attacker can exploit CVE-2023-3488 by using a malformed GBL file to leak data from the Secure stack.
Yes, updating to Silicon Labs GSDK version 4.3.1 or later fixes CVE-2023-3488.
More information about CVE-2023-3488 can be found in the references provided: [Link 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000Wi3HwQAJ?operationContext=S1), [Link 2](https://github.com/SiliconLabs/gecko_sdk/releases).