Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4fc-4f5m-5hhw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

EPSS

Процентиль: 10%
0.00036
Низкий

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 6.8
nvd
больше 4 лет назад

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

suse-cvrf
больше 4 лет назад

Security update for solo

EPSS

Процентиль: 10%
0.00036
Низкий

Дефекты

CWE-326