# Silicon Labs Security Advisory A-00000492 : Security Advisory for Vulnerabilities in Mbed TLS 3.4.1 and earlier Flags: Security, OpenThread CVSS Severity: Medium CVSS String: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:R](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:R) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.4.1 and earlier | GSDK | 4.3.x and earlier | [CVE-2023-41097](https://nvd.nist.gov/vuln/detail/CVE-2023-41097), [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) | | OpenThread | 2.3.2 through 2.2.0 | GSDK | 4.3.x and earlier | [CVE-2023-41097](https://nvd.nist.gov/vuln/detail/CVE-2023-41097), [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) | ### Source Product Impact Details | Vulnerability ID | CVSS Severity | Base Score | Temporal Score | CVSS 3.1 Vector String | | --- | --- | --- | --- | --- | | MT-193F942 | Medium | 5.4, Medium | 5.0, Medium | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L/E:H/RL:O/RC:R | | MT-025BED9, CVE-2023-41097 | Medium | 4.6, Medium | 4.2, Medium | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C | | CVE-2023-45199 | Medium | 8.1, High | 6.8, Medium | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:R | - EFx32x devices including SoCs and Modules using Mbed TLS 3.4.1 (Mbed TLS 3.2.1 shipped with GSDK 4.3.x) and earlier are potentially affected. Consult the following subsections for additional information per vulnerability - Products using Mbed TLS 3.5.0 (shipped with GSDK 4.4.0) and later are unaffected MT-193F942 - Only products using cipher suites with null cipher (TLS_nnn_WITH_NULL_ …) or RC4 (TLS_nnn_WITH_RC4_128_ …) are affected by this vulnerability - These ciphers suites are weak or deprecated and are not enabled by default in GSDK, if you have not enabled these suites manually your product is unaffected MT-025BED9 - Products using AES-CBC or RSA OEAP shipped with GSDK 4.3.2 and earlier may be affected by this vulnerability depending on the compiler and optimization options used - Products using software compiled with IAR are affected by this vulnerability - This vulnerability has not been observed in software compiled with GCC, however test coverage is not sufficient to guarantee this vulnerability is not present across all configurations and compiler options [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) - Products using OpenThread SDK between 2.2.0.0 and 2.3.2.0 (GSDK between 4.2.0 and 4.3.2) are affected by this vulnerability - Products using Mbed TLS between 3.2.0 and 3.4.1, (between GSDK 4.2.0 and 4.3.2) operating as TLS clients or servers with support for signature-based authentication (i.e. any non-PSK key exchange) are affected by this vulnerability ## CVE ID(s) - Mbed TLS has not assigned a CVE for MT-193F942 at the time of this publication - Because Mbed TLS does not guarantee constant-time operation, no CVE will be assigned to MT-025BED9, however in the course of investigation of this defect, [CVE-2023-41097](https://nvd.nist.gov/vuln/detail/CVE-2023-41097) [1] has been reserved for a vulnerability of similar nature discovered in the source for Silicon Labs’ implementation of CBC PKCS7 padding calculations - [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) [2] can be found in the NIST National Vulnerability Database ## Description - Refer to the following subsections for technical details for each vulnerability MT-193F942 - A bug in TLS MAC length calculation may cause a buffer overread - For more information about this vulnerability, refer to Mbed TLS github commit 193F942 [3] MT-025BED9 - Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information - For more information about this vulnerability, refer to Mbed TLS github commit 025bed9 [4] [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) - Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets - For more information about this vulnerability consult Mbed TLS Security Advisory 2023-10-2 [5] ### Fix/Workaround - These vulnerabilities were addressed in the release of Mbed TLS 3.5.0 (shipped with GSDK 4.4.0). Affected users should update to GSDK 4.4.0 or later - Instructions for downloading/updating the GSDK [6] and for upgrading a project to use a new GSDK version [7] can be found in the Simplicity Studio Users Guide - NULL Cipher and RC4 are weak/deprecated and should remain at their default disabled configuration ## Attribution - These vulnerabilities were reported to Silicon Labs by TrustedFirmware.org - [CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) was reported by OSS-Fuzz [1] [https://nvd.nist.gov/vuln/detail/CVE-2023-41097](https://nvd.nist.gov/vuln/detail/CVE-2023-41097) [2] [https://nvd.nist.gov/vuln/detail/CVE-2023-45199](https://nvd.nist.gov/vuln/detail/CVE-2023-45199) [3] [https://github.com/Mbed-TLS/mbedtls/commit/193f94276e100603ce8cd1450e7f58e703a86bcc](https://github.com/Mbed-TLS/mbedtls/commit/193f94276e100603ce8cd1450e7f58e703a86bcc) [4] [https://github.com/Mbed-TLS/mbedtls/commit/025bed9eb700a7246207eac230e2cd563c62b2d1](https://github.com/Mbed-TLS/mbedtls/commit/025bed9eb700a7246207eac230e2cd563c62b2d1) [5] [https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-2/](https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2023-10-2/) [6] [https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar#install](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar#install) [7] [https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version) ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.1 | 2024-FEB-09 | Changed “Impacted Products:CVE-2023-45199” first bullet to read: “OpenThread between 2.2.0 and 3.2.0” to reflect that this vulnerability was introduced in 2.2.0 | | 1.0 | 2023-DEC-21 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)