Description
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.
Problem types
CWE-191 Integer Underflow (Wrap or Wraparound)
Product status
Any version
Any version
Credits
SecMate, including Maxime Rossi Bellom and Ramtine Tofighi Shirazi
References
community.silabs.com/068Vm00000e1UTF