PT-2024-19442 · Gecko Sdk · Gecko Sdk
Published
2024-02-21
·
Updated
2024-09-27
·
CVE-2024-22473
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Gecko SDK versions through 4.4.0
Description
The issue arises from the use of a True Random Number Generator (TRNG) before its initialization by the ECDSA signing driver when exiting low-power modes (EM2/EM3) on Virtual Secure Vault (VSE) devices. This defect may allow an attacker to recreate keys, potentially enabling signature spoofing.
Recommendations
For Gecko SDK versions through 4.4.0, update to a version newer than 4.4.0 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gecko Sdk