CVE-2022-24936

Published

Severity

CVSS v3:
9.1 CRITICAL
CVSS v2:
N/A

Description

Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:silabs:gecko_bootloader:*:*:*:*:*:*:*:*n/a4.0.1 (including)*

External Links