Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devices
CVE-2022-24936

8.3HIGH

Key Information:

Vendor
Silabs.com
Vendor
CVE Published:
2 November 2022

Summary

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

Affected Version(s)

Gecko Bootloader 0 <= 4.0.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-24936 : Gecko Standalone Bootloader vulnerability may allow bypassing application secure boot in some Series 2 devices | SecurityVulnerability.io