Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devices
CVE-2022-24936
8.3HIGH
What is CVE-2022-24936?
Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.
Affected Version(s)
Gecko Bootloader 0 <= 4.0.1