First published: Fri May 21 2021(Updated: )
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nordicsemi Nrf52840 Firmware | <=2020-10-19 | |
Nordicsemi Nrf52840 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-27211 is medium with a CVSS score of 5.7.
The vulnerable software version for CVE-2020-27211 is Nordic Semiconductor nRF52840 firmware up to and including 2020-10-19.
The flash read-out protection (APPROTECT) in CVE-2020-27211 can be bypassed by injecting a fault during the boot phase.
More information about CVE-2020-27211 can be found at the following references: - [1] https://eprint.iacr.org/2021/640 - [2] https://infocenter.nordicsemi.com/pdf/in_133_v1.0.pdf - [3] https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
The CWE category of CVE-2020-27211 is CWE-203 (Information Exposure Through Discrepancy).