Ralim IronOS Vulnerability in BLE Stack TinyCrypt Module Prior to v2.23-rc3
Vulnerability
A vulnerability exists in Ralim IronOS versions prior to v2.23-rc3, specifically within the Bluetooth Low Energy (BLE) stack's TinyCrypt module. The issue arises in the 'ecc_dsa.C' file, where a function 'uECC_sign_with_k()' was cloned from the micro-ecc library but missed a critical security patch. This oversight could potentially be exploited, similar to the original vulnerability addressed in the micro-ecc repository.
Impact
Exploitation of this vulnerability could lead to a security issue in the digital signature algorithm implementation, potentially allowing for unauthorized signature generation or verification.
Remediation
Users can update to Ralim IronOS version 2.23-rc3 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
