Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24936


Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.


Published

2022-11-02T18:15:10.470

Last Modified

2024-11-21T06:51:25.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silabs gecko_bootloader ≤ 4.0.1 Yes

References