PT-2024-19442 · Gecko Sdk · Gecko Sdk

Published

2024-02-21

·

Updated

2024-09-27

·

CVE-2024-22473

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gecko SDK versions through 4.4.0
Description The issue arises from the use of a True Random Number Generator (TRNG) before its initialization by the ECDSA signing driver when exiting low-power modes (EM2/EM3) on Virtual Secure Vault (VSE) devices. This defect may allow an attacker to recreate keys, potentially enabling signature spoofing.
Recommendations For Gecko SDK versions through 4.4.0, update to a version newer than 4.4.0 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-22473

Affected Products

Gecko Sdk