Описание
Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.
Ссылки
- Permissions RequiredVendor Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.1 (включая)
cpe:2.3:a:silabs:gecko_bootloader:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00446
Низкий
8.3 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-119
CWE-787
Связанные уязвимости
CVSS3: 9.1
github
больше 3 лет назад
Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.
EPSS
Процентиль: 63%
0.00446
Низкий
8.3 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-119
CWE-787