CVE-2020-27211: Medium severity nordicsemi nrf52840 vulnerability
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27211?
The severity of CVE-2020-27211 is medium with a CVSS score of 5.7.
What is the vulnerable software version for CVE-2020-27211?
The vulnerable software version for CVE-2020-27211 is Nordic Semiconductor nRF52840 firmware up to and including 2020-10-19.
How can the flash read-out protection (APPROTECT) be bypassed in CVE-2020-27211?
The flash read-out protection (APPROTECT) in CVE-2020-27211 can be bypassed by injecting a fault during the boot phase.
Where can I find more information about CVE-2020-27211?
More information about CVE-2020-27211 can be found at the following references: - [1] https://eprint.iacr.org/2021/640 - [2] https://infocenter.nordicsemi.com/pdf/in_133_v1.0.pdf - [3] https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
What is the CWE category of CVE-2020-27211?
The CWE category of CVE-2020-27211 is CWE-203 (Information Exposure Through Discrepancy).