Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41097


An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM potentially allows Padding Oracle Crypto Attack on CBC PKCS7.This issue affects GSDK: through 4.4.0.


Published

2023-12-21T21:15:08.020

Last Modified

2024-11-21T08:20:34.237

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-208
    CWE-327
  • Type: Primary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silabs gecko_software_development_kit ≤ 4.4.0 Yes

References