PoC Index

CVE-2020-27208

MEDIUM 6.8EPSS 0.3%

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

CVSS v3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
0.33% chance of exploitation in the next 30 days, 25th percentile
Published
2021-05-21
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related