CVE-2021-29415: Medium severity nordicsemi nrf52840 vulnerability
Published May 21, 2021
·Updated
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the private ECC key used during an ECDSA operation.
Affected Software
2 affected components
NordicSemi Nrf52840 Firmware<=2021-03-29
NordicSemi nRF52840
Event History
May 21, 2021
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-29415.
2
What is the severity of CVE-2021-29415?
The severity of CVE-2021-29415 is medium with a severity value of 5.5.
3
What is the affected software for CVE-2021-29415?
The affected software for CVE-2021-29415 is Nordicsemi Nrf52840 Firmware up to and including version 2021-03-29.
4
How can an adversary exploit CVE-2021-29415?
An adversary can exploit CVE-2021-29415 to recover the private ECC key used during an ECDSA operation.
5
Is there a fix available for CVE-2021-29415?
Please refer to the references provided for information on any available fixes for CVE-2021-29415.