# Silicon Labs Security Advisory A-00000530 : Improper certificate validation and session fixation reported in Mbed TLS Flags: Security CVSS Severity: Critical CVSS String: [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) ## Product Impact | Product | Impacted Version | Main SDK | Impacted Version | CVE | | --- | --- | --- | --- | --- | | Mbed TLS | 3.6.0 and earlier | SiSDK | 2024.6.x and earlier | [CVE-2024-45159](https://nvd.nist.gov/vuln/detail/CVE-2024-45159), [CVE-2023-52353](https://nvd.nist.gov/vuln/detail/CVE-2023-52353), [CVE-2024-45157](https://nvd.nist.gov/vuln/detail/CVE-2024-45157) | | Mbed TLS | 3.6.0 and earlier | GSDK | All released versions | [CVE-2024-45159](https://nvd.nist.gov/vuln/detail/CVE-2024-45159), [CVE-2023-52353](https://nvd.nist.gov/vuln/detail/CVE-2023-52353), [CVE-2024-45157](https://nvd.nist.gov/vuln/detail/CVE-2024-45157) | ### Source Product Impact Details - EFR32 devices- ICs and modules operating with - Simplicity SDK 2024.6.4 and below - Gecko SDK Suite 4.4.6 and below - The CVEs listed in the following table are reserved for these vulnerabilities. | CVE Number | Description | | --- | --- | | [CVE-2024-45159](https://nvd.nist.gov/vuln/detail/CVE-2024-45159) | Limited authentication bypass in TLS 1.3 optional client authentication | | [CVE-2023-52353](https://nvd.nist.gov/vuln/detail/CVE-2023-52353) | Server refuses TLS 1.3 connection from peer if peer used TLS 1.2 previously | | [CVE-2024-45157](https://nvd.nist.gov/vuln/detail/CVE-2024-45157) | CTR_DRBG prioritized over HMAC_DRBG as the PSA DRBG | ## Description - EFR32 devices- ICs and modules operating with either Simplicity SDK version 2024.6.4 or earlier, or Gecko SDK Suite version 4.4.6 or earlier - TLS server is not able to verify client certificate options “keyUsage” and “extKeyUsage” - Maximum negotiable TLS version is mishandled. For example, a server refuses TLS1.3 connections from a peer if that peer used TLS1.2 to connect with the server previously - PSA cryptography subsystem uses CTR_DRBG by default rather than HMAC_DRBG, even though CTR_DRBG is weaker against side channel attacks than HMAC_DRBG ### Fix/Workaround - To mitigate the risk upgrade to Simplicity SDK 2024.12.0, or later - Instructions for [updating the Simplicity SDK](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-about-the-launcher/toolbar#install) and for [upgrading a project to a new Simplicity SDK version](https://docs.silabs.com/simplicity-studio-5-users-guide/latest/ss-5-users-guide-getting-started/project-upgrade-new-gsdk-version) can be found in the Simplicity Studio Users Guide - Please refer to the [Simplicity SDK 2024.12.0](https://www.silabs.com/documents/public/release-notes/gecko-platform-release-notes-5.1.0.0.pdf) release notes for more information regarding the fix implemented - Currently Silicon labs have no plans to address the risks in GSDK, which are mentioned in this advisory ## Attribution - [CVE-2024-45159](https://nvd.nist.gov/vuln/detail/CVE-2024-45159) , [CVE-2023-52353](https://nvd.nist.gov/vuln/detail/CVE-2023-52353) and [CVE-2024-45157](https://nvd.nist.gov/vuln/detail/CVE-2024-45157) were reported by TrustedFirmware ## Revision History | Rev | Date | Description of Changes | | --- | --- | --- | | 1.0 | 2025-APR-17 | Initial publication | ## Additional Resources - Security policy: [https://www.silabs.com/security](https://www.silabs.com/security) - Technical support: [https://www.silabs.com/support](https://www.silabs.com/support)