CVE-2023-41097: Potential Timing vulnerability in CBC PKCS7 padding calculations
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41097?
CVE-2023-41097 is categorized as a potential medium severity vulnerability due to its covert timing channel that could enable a Padding Oracle attack.
How do I fix CVE-2023-41097?
To mitigate CVE-2023-41097, it is recommended to upgrade to a version of the Gecko Software Development Kit greater than 4.4.0.
What types of attacks does CVE-2023-41097 enable?
CVE-2023-41097 enables a Padding Oracle Crypto Attack, specifically on CBC PKCS7, through observable timing discrepancies.
Which software versions are affected by CVE-2023-41097?
CVE-2023-41097 affects all versions of the Silicon Labs Gecko Software Development Kit up to and including 4.4.0.
Where can I find more information about CVE-2023-41097?
More information regarding CVE-2023-41097 can typically be found in the official release notes from Silicon Labs.