Vulnerabilities > Raspberrypi > Raspberry PI 3 Model B Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-08-11 CVE-2021-38545 Unspecified vulnerability in Raspberrypi products
Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack.
network
raspberrypi
4.3
2019-04-04 CVE-2018-18068 Exposure of Resource to Wrong Sphere vulnerability in Raspberrypi Raspberry PI 3 Model B+ Firmware
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging.
network
low complexity
raspberrypi CWE-668
critical
10.0