CVE-2025-14547: ECJ-PAKE Integer Underflow Vulnerability in Silicon Labs PSA Crypto and SE Manager APIs
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14547?
CVE-2025-14547 is classified as a medium severity vulnerability due to its potential to cause system instability.
How do I fix CVE-2025-14547?
To fix CVE-2025-14547, update to the latest version of the Silicon Labs PSA Crypto and SE Manager APIs that address the integer underflow issue.
What causes the CVE-2025-14547 vulnerability?
CVE-2025-14547 is caused by an integer underflow in the EC-JPAKE APIs during zero-knowledge proof parsing.
Who is affected by CVE-2025-14547?
CVE-2025-14547 affects users of Silicon Labs PSA Crypto and SE Manager that utilize the vulnerable EC-JPAKE APIs.
What are the potential impacts of exploiting CVE-2025-14547?
Exploitation of CVE-2025-14547 can lead to a hard fault, resulting in temporary system unavailability.