VYPR

Gecko Software Development Kit

by Silabs

CVEs (30)

  • CVE-2023-32098MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.01

    Compiler removal of buffer clearing in sli_se_sign_message in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2481MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-1132MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-41097MedDec 21, 2023
    risk 0.30cvss 4.6epss 0.00

    An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

  • CVE-2023-3488LowJul 28, 2023
    risk 0.25cvss 3.8epss 0.00

    Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

  • CVE-2023-2747LowJun 15, 2023
    risk 0.20cvss 3.1epss 0.00

    The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.

  • CVE-2023-32097LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-32096LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-0965LowMay 18, 2023
    risk 0.20cvss 3.1epss 0.00

    Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and earlier results in key material duplication to RAM.

  • CVE-2023-2687LowJun 2, 2023
    risk 0.19cvss 2.9epss 0.00

    Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.

Page 2 of 2