"value":"TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-908 Use of Uninitialized Resource",
"cweId":"CWE-908"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-330 Use of Insufficiently Random Values",
"cweId":"CWE-330"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",