CVE-2023-4020: Silabs Gecko Software Development Kit
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.
Affected products
- Silabs Gecko Software Development Kit: from 1.0.0, before 4.4.0 (fixed in 4.4.0)
Published 2023-12-15. Last modified 2026-06-17.