PT-2024-19442 · Gecko Sdk · Gecko Sdk

CVE-2024-22473

·

Published

2024-02-21

·

Updated

2024-09-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gecko SDK versions through 4.4.0
Description The issue arises from the use of a True Random Number Generator (TRNG) before its initialization by the ECDSA signing driver when exiting low-power modes (EM2/EM3) on Virtual Secure Vault (VSE) devices. This defect may allow an attacker to recreate keys, potentially enabling signature spoofing.
Recommendations For Gecko SDK versions through 4.4.0, update to a version newer than 4.4.0 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-22473

Affected Products

Gecko Sdk