CVE-2023-2747
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized.
Affected (1)
Products: Silabs: Gecko Software Development Kit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.2.1 |
Related CWEs
CWE-1204
Generation of Weak Initialization Vector (IV)
The product uses a cryptographic primitive that uses an Initialization
Vector (IV), but the product does not generate IVs that are
sufficiently unpredictable or unique according to the expected
cryptographic requirements for that primitive.
CWE-908
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
References (4)
Source: product-security@silabs.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.