Vulnerabilities > CVE-2023-3488 - Use of Uninitialized Resource vulnerability in Silabs Gecko Software Development KIT

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
silabs
CWE-908

Summary

Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.

Common Weakness Enumeration (CWE)