CVE-2024-22473

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
Configurations

No configuration.

History

27 Sep 2024, 17:15

Type Values Removed Values Added
CWE CWE-330
CWE-338
CWE-908
CWE-1279
CWE-331
Summary (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0. (en) TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

21 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 19:15

Updated : 2024-09-27 17:15


NVD link : CVE-2024-22473

Mitre link : CVE-2024-22473

CVE.ORG link : CVE-2024-22473


JSON object : View

Products Affected

No product.

CWE
CWE-1279

Cryptographic Operations are run Before Supporting Units are Ready

CWE-331

Insufficient Entropy