Back to search
CVE-2020-27208
Published: May 21, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.aisec.fraunhofer.de/en/FirmwareProtection.html
x_refsource_MISC
https://twitter.com/SoloKeysSec
x_refsource_MISC
https://solokeys.com
x_refsource_MISC
https://eprint.iacr.org/2021/640
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now