CVE-2024-22473CWE-1279CWE-331
Uninitialized TRNG used for ECDSA after EM2/EM3 sleep for VSE devices
Medium · published February 21, 2024
What it is
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
The record
Technical detail
- CVSS v3.1
- 6.8 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00396 · 32.8th percentile
- Weaknesses
- CWE-1279 · Cryptographic Operations are run Before Supporting Units are Ready; CWE-331 · Insufficient Entropy
- Published
- 2024-02-21T18:13Z
EPSS history
Timeline