CVE-2020-27208

CVE-2020-27208

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

Source: CVE-2020-27208

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다