CRITICAL🇵🇱 Wersja polska

CVE-2023-4280

CVSS 9.3v3.1pub. 2024-01-02upd. 2024-11-21

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

🤖 AI Analysis
How it works

The TrustZone implementation in Gecko SDK does not properly validate input data passed from the untrusted execution area (Normal World) to the trusted area (Secure World). Out-of-bounds read (CWE-125) and out-of-bounds write (CWE-787) errors indicate that an attacker can pass specially crafted input data causing reads or writes outside the designated buffers. As a result, it is possible to cross the TrustZone isolation boundary and gain access to protected memory without required permissions.

Impact

An attacker can read or modify the contents of a trusted memory region, which may lead to disclosure of sensitive data (e.g., cryptographic keys), privilege escalation, or compromise of system integrity and availability.

Mitigation & patch

Update Gecko SDK to a version higher than 4.3.x according to manufacturer recommendations available at https://community.silabs.com/069Vm0000004NinIAE. Apply patches available from the manufacturer according to the references.

Who is affected

Silicon Labs Gecko Software Development Kit (Gecko SDK) version 4.3.x and earlier, covering devices utilizing TrustZone implementation.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Silabs Gecko Software Development Kit

    APP
    Silabs
    1.0.0 – 4.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-45318CRITICAL10.0PL ✓same product

Heap-based buffer overflow w serwerze HTTP biblioteki uC-HTTP — RCE

CVE-2023-4020CRITICAL9.0PL ✓same product

Błąd walidacji wejścia w TrustZone SDK Silicon Labs — dostęp do pamięci bezpiecznej

CVE-2023-27882CRITICAL9.0PL ✓same product

Heap-based buffer overflow w HTTP Server Weston Embedded uC-HTTP

CVE-2023-28379CRITICAL9.0PL ✓same product

Uszkodzenie pamięci w HTTP Server Weston Embedded uC-HTTP — RCE

CVE-2023-25181CRITICAL9.0PL ✓same product

Heap-based buffer overflow w serwerze HTTP Weston Embedded uC-HTTP – RCE