Vulnerabilities > CVE-2020-27211 - Information Exposure Through Discrepancy vulnerability in Nordicsemi Nrf52840 Firmware 20201019
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 | |
Hardware | 1 |
Common Weakness Enumeration (CWE)
References
- https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
- https://eprint.iacr.org/2021/640
- https://infocenter.nordicsemi.com/pdf/in_133_v1.0.pdf
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.html
- https://www.aisec.fraunhofer.de/de/das-institut/wissenschaftliche-exzellenz/security-and-trust-in-open-source-security-tokens.html