CVE-2024-22473CWE-1279CWE-331

Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices

Medium · published February 21, 2024

CVSS v3.1
6.8
EPSS
0%
Percentile
32.8
In the wild
Unconfirmed
What it is

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00396 · 32.8th percentile
Weaknesses
CWE-1279 · Cryptographic Operations are run Before Supporting Units are Ready; CWE-331 · Insufficient Entropy
Published
2024-02-21T18:13Z
EPSS history
Timeline
  • 21 FEB 18:13Z
    Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
    cvelistv5