CVE-2023-41097

A

n Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.

Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:gecko_software_development_kit:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.6
References () https://github.com/SiliconLabs/gecko_sdk/releases - Release Notes () https://github.com/SiliconLabs/gecko_sdk/releases - Release Notes
References () https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000007rArIAI?operationContext=S1 - Permissions Required () https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000007rArIAI?operationContext=S1 - Permissions Required

25 Sep 2024, 17:15

Type Values Removed Values Added
Summary (en) An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0. (en) An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.
CWE CWE-385 CWE-327

Information

Published : 2023-12-21 21:15

Updated : 2024-11-21 08:20


NVD link : CVE-2023-41097

Mitre link : CVE-2023-41097

CVE.ORG link : CVE-2023-41097


JSON object : View

CWE
CWE-208

Observable Timing Discrepancy

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-203

Observable Discrepancy