First published: Thu Dec 21 2023(Updated: )
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silicon Labs Gecko SDK | <=4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41097 is categorized as a potential medium severity vulnerability due to its covert timing channel that could enable a Padding Oracle attack.
To mitigate CVE-2023-41097, it is recommended to upgrade to a version of the Gecko Software Development Kit greater than 4.4.0.
CVE-2023-41097 enables a Padding Oracle Crypto Attack, specifically on CBC PKCS7, through observable timing discrepancies.
CVE-2023-41097 affects all versions of the Silicon Labs Gecko Software Development Kit up to and including 4.4.0.
More information regarding CVE-2023-41097 can typically be found in the official release notes from Silicon Labs.