Lucene search

K
cve[email protected]CVE-2023-41096
HistoryOct 26, 2023 - 2:15 p.m.

CVE-2023-41096

2023-10-2614:15:08
CWE-311
web.nvd.nist.gov
11
cve-2023-41096
encryption
security keys
silicon labs
ember znet sdk
vulnerability
nvd
arm
flash

6.8 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules)
allows potential modification or extraction of network credentials stored in flash.

This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.

Affected configurations

NVD
Node
silabsemberznet_sdkRange7.3.1.0

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "SecureVault High"
    ],
    "platforms": [
      "32 bit",
      "ARM"
    ],
    "product": "Ember ZNet SDK",
    "repo": "https://github.com/SiliconLabs/gecko_sdk",
    "vendor": "silabs.com",
    "versions": [
      {
        "status": "unaffected",
        "version": "7.3.2"
      }
    ]
  }
]

6.8 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.3 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Related for CVE-2023-41096