Ralim IronOS Vulnerability in BLE Stack TinyCrypt Module Prior to v2.23-rc3

Vulnerability

A vulnerability exists in Ralim IronOS versions prior to v2.23-rc3, specifically within the Bluetooth Low Energy (BLE) stack's TinyCrypt module. The issue arises in the 'ecc_dsa.C' file, where a function 'uECC_sign_with_k()' was cloned from the micro-ecc library but missed a critical security patch. This oversight could potentially be exploited, similar to the original vulnerability addressed in the micro-ecc repository.

Impact

Exploitation of this vulnerability could lead to a security issue in the digital signature algorithm implementation, potentially allowing for unauthorized signature generation or verification.

Remediation

Users can update to Ralim IronOS version 2.23-rc3 or later to address this vulnerability.

Added: Jan 27, 2026, 9:32 AM
Updated: Jan 27, 2026, 3:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.5
remediation
0.0
relevance
2.3
threat
0.0
urgency
10.0
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.