CVE-2023-32099 MEDIUM

CVE-2023-32099: Key duplication in GSDK

Vendor Silabs.com
Product Gecko Platform
Weakness CWE-14
Published May 18, 2023
Last update January 21, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

Key dates

02Disclosure timeline

May 18, 2023 CVE published
January 21, 2025 Record updated