# Silicon Labs Security Advisory A-00000514 : Security Advisory for Vulnerabilities in Mbed TLS 3.5.2 and earlier Flags: Security CVSS Severity: High CVSS String: Varies ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.5.2 and earlier | SiSDK | 2024.6.x and earlier | [CVE-2024-23170](https://nvd.nist.gov/vuln/detail/CVE-2024-23170), [CVE-2024-23775](https://nvd.nist.gov/vuln/detail/CVE-2024-23775), [CVE-2024-28755](https://nvd.nist.gov/vuln/detail/CVE-2024-28755), [CVE-2024-28836](https://nvd.nist.gov/vuln/detail/CVE-2024-28836), [CVE-2024-23744](https://nvd.nist.gov/vuln/detail/CVE-2024-23744), [CVE-2024-28960](https://nvd.nist.gov/vuln/detail/CVE-2024-28960) | | Mbed TLS | 3.5.2 and earlier | GSDK | all versions | [CVE-2024-23170](https://nvd.nist.gov/vuln/detail/CVE-2024-23170), [CVE-2024-23775](https://nvd.nist.gov/vuln/detail/CVE-2024-23775), [CVE-2024-28755](https://nvd.nist.gov/vuln/detail/CVE-2024-28755), [CVE-2024-28836](https://nvd.nist.gov/vuln/detail/CVE-2024-28836), [CVE-2024-23744](https://nvd.nist.gov/vuln/detail/CVE-2024-23744), [CVE-2024-28960](https://nvd.nist.gov/vuln/detail/CVE-2024-28960) | ### Source Product Impact Details - The following vulnerabilities have been submitted against Mbed TLS 3.5.x and earlier which is used in Simplicity SDK (SiSDK) 2024.06.x and earlier, as well as all versions of Gecko SDK and may affect Silicon Labs customers - Refer to the information contained in the table below to determine if you are impacted, and consult the CVE link for more information on the vulnerability ## CVE ID(s) - The following CVEs have been reserved for these issues | CVE Number | Product(s) Potentially Affected | Impacted Version(s) | | --- | --- | --- | | [CVE-2024-23170](https://nvd.nist.gov/vuln/detail/CVE-2024-23170) | Devices using the implementation of RSA included in Mbed TLS. Silicon Labs products do not use RSA and are unaffected. | SiSDK 2024.6.x and earlier, GSDK all versions | | [CVE-2024-23775](https://nvd.nist.gov/vuln/detail/CVE-2024-23775) | Devices using Mbed TLS to process x.509 extensions. Silicon Labs Matter Devices do not use this library and are unaffected. | SiSDK 2024.6.x and earlier, GSDK all versions| | [CVE-2024-28755](https://nvd.nist.gov/vuln/detail/CVE-2024-28755) [1], [CVE-2024-28836](https://nvd.nist.gov/vuln/detail/CVE-2024-28836) [1], [CVE-2024-23744](https://nvd.nist.gov/vuln/detail/CVE-2024-23744) [2] | Devices operating as TLS 1.3 servers. Silicon Labs products do not operate TLS 1.3 servers and are unaffected. | SiSDK 2024.6.x and earlier, GSDK all versions | | [CVE-2024-28960](https://nvd.nist.gov/vuln/detail/CVE-2024-28960) [1] | All VSE devices are affected. This includes EFX32xG22 and EFR32xG27. All TrustZone aware projects using PSA Crypto APIs with array arguments are affected | SiSDK 2024.6.x and earlier, GSDK all versions | Please note: As of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioning scheme has changed from Gecko SDK vX.Y.Z to Simplicity SDK YYYY.MM.Patch# ## Description - These vulnerabilities occur in a 3rd party library distributed in SiSDK and GSDK. - This notice is only intended to notify that an affected 3rd party component is included in Silicon Labs products. Please refer to the corresponding CVE(s) for technical details. ### Fix/Workaround - All currently shipping releases of GSDK contain affected versions of Mbed TLS - Affected users should upgrade to SiSDK 2024.12.0, or later. - Instructions for [downloading/updating the SDK](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar%23install) and for [upgrading a project](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version) can be found in the Simplicity Studio Users Guide. ## Attribution - Please refer to the corresponding CVE(s) for attribution details ### References [1] These CVEs apply to Mbed TLS 3.5.x before 3.6.0, but Silicon Labs never distributed any version between 3.5.3 and 3.5.9 [2] This CVE applies to MbedTLS 3.5.1, but Silicon Labs only distributed 3.5.0 ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.2 | 2026-MAY-01 | Updated impacted products for CVE-2024-28960 | | 1.1 | 2025-AUG-07 | Updated impacted and fixed versions | | 1.0 | 2024-JUL-08 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)