First published: Fri Dec 15 2023(Updated: )
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silicon Labs Gecko SDK | >=1.0.0<4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4020 has been classified as a high-severity vulnerability due to its potential for unauthorized memory access.
To mitigate CVE-2023-4020, ensure you update to an unaffected version of the Silicon Labs Gecko SDK beyond version 4.4.0.
CVE-2023-4020 allows an attacker to read from or write to the secure region of memory, compromising its integrity.
CVE-2023-4020 affects versions of Silicon Labs Gecko SDK from 1.0.0 to 4.4.0.
Yes, exploiting CVE-2023-4020 could potentially allow an attacker to execute arbitrary code by manipulating secure memory.