CVE-2023-4020: Silabs Gecko Software Development Kit

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.

Affected products

  • Silabs Gecko Software Development Kit: from 1.0.0, before 4.4.0 (fixed in 4.4.0)

Published 2023-12-15. Last modified 2026-06-17.