CVE-2023-4020: Unvalidated input in Silicon Labs PSA Attestation service leads to secure memory access from non-secure memory
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4020?
CVE-2023-4020 has been classified as a high-severity vulnerability due to its potential for unauthorized memory access.
How do I fix CVE-2023-4020?
To mitigate CVE-2023-4020, ensure you update to an unaffected version of the Silicon Labs Gecko SDK beyond version 4.4.0.
What impact does CVE-2023-4020 have on secure memory?
CVE-2023-4020 allows an attacker to read from or write to the secure region of memory, compromising its integrity.
Which versions of Silicon Labs Gecko SDK are affected by CVE-2023-4020?
CVE-2023-4020 affects versions of Silicon Labs Gecko SDK from 1.0.0 to 4.4.0.
Can CVE-2023-4020 lead to remote code execution?
Yes, exploiting CVE-2023-4020 could potentially allow an attacker to execute arbitrary code by manipulating secure memory.