CVE-2024-22473

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
21/02/2024
Last modified:
12/02/2025

Description

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:* 4.4.0 (including)