CVE-2020-27208
Last modified
CVE-2020-27208 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solokeys | Solo Firmware | 4.0.0 |
| Solokeys | Somu Firmware | All versions |
| Nitrokey | Fido2 Firmware | All versions |
References
- https://eprint.iacr.org/2021/640Third Party Advisory
- https://github.com/solokeys/solo/commit/a9c02cd354f34b48195a342c7f524abdef5cbcecPatch, Third Party Advisory
- https://solokeys.comProduct
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.htmlExploit, Third Party Advisory
- https://eprint.iacr.org/2021/640Third Party Advisory
- https://github.com/solokeys/solo/commit/a9c02cd354f34b48195a342c7f524abdef5cbcecPatch, Third Party Advisory
- https://solokeys.comProduct
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27208?
How severe is CVE-2020-27208?
How do I fix CVE-2020-27208?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27195HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.1…9.1
- CVE-2020-27196An issue was discovered in PlayJava in Play Framework 2.6.0 …7.5
- CVE-2020-27197TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTA…9.8
- CVE-2020-27199The Magic Home Pro application 1.5.1 for Android allows Auth…7.5
- CVE-2020-2720Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…5.4
- CVE-2020-27207Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, rel…7.5
- CVE-2020-27209The ECDSA operation of the micro-ecc library 1.0 is vulnerab…7.5
- CVE-2020-2721Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…6.5
- CVE-2020-27211Nordic Semiconductor nRF52840 devices through 2020-10-19 hav…5.7
- CVE-2020-27212STMicroelectronics STM32L4 devices through 2020-10-19 have i…7
- CVE-2020-27213An issue was discovered in Ethernut Nut/OS 5.1. The code tha…7.5
- CVE-2020-27216In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.…7
Are you affected by CVE-2020-27208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
