CVE-2023-4280

critical

Description

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

References

https://github.com/SiliconLabs/gecko_sdk

https://community.silabs.com/069Vm0000004NinIAE

Details

Source: Mitre, NVD

Published: 2024-01-02

Updated: 2024-01-09

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical