First published: Tue Jan 02 2024(Updated: )
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silicon Labs Gecko SDK | >=1.0.0<=4.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4280 has been classified as a high severity vulnerability due to the potential for attackers to access secure memory regions.
To fix CVE-2023-4280, upgrade the Silicon Labs Gecko SDK to version 4.3.3 or later.
CVE-2023-4280 allows untrusted input to gain unauthorized access to the trusted memory region, potentially compromising sensitive data.
CVE-2023-4280 affects versions of the Gecko SDK from 1.0.0 to 4.3.2.
Currently, the recommended approach for CVE-2023-4280 is to upgrade to a non-vulnerable version rather than using a workaround.