CVE-2020-27208
Last modified
CVE-2020-27208 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solokeys | Solo Firmware | 4.0.0 |
| Solokeys | Somu Firmware | All versions |
| Nitrokey | Fido2 Firmware | All versions |
References
- https://eprint.iacr.org/2021/640Third Party Advisory
- https://github.com/solokeys/solo/commit/a9c02cd354f34b48195a342c7f524abdef5cbcecPatch, Third Party Advisory
- https://solokeys.comProduct
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.htmlExploit, Third Party Advisory
- https://eprint.iacr.org/2021/640Third Party Advisory
- https://github.com/solokeys/solo/commit/a9c02cd354f34b48195a342c7f524abdef5cbcecPatch, Third Party Advisory
- https://solokeys.comProduct
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27208?
How severe is CVE-2020-27208?
How do I fix CVE-2020-27208?
Are you affected by CVE-2020-27208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
