CVE-2020-27208 Information
Jun 07, 2022
cve
Description
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://twitter.com/SoloKeysSec https://solokeys.com https://eprint.iacr.org/2021/640 https://www.aisec.fraunhofer.de/en/FirmwareProtection.html https://github.com/solokeys/solo/commit/a9c02cd354f34b48195a342c7f524abdef5cbcec https://www.aisec.fraunhofer.de/de/das-institut/wissenschaftliche-exzellenz/security-and-trust-in-open-source-security-tokens.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.8
Share on: