First published: Fri May 21 2021(Updated: )
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the private ECC key used during an ECDSA operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nordicsemi Nrf52840 Firmware | <=2021-03-29 | |
Nordicsemi Nrf52840 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-29415.
The severity of CVE-2021-29415 is medium with a severity value of 5.5.
The affected software for CVE-2021-29415 is Nordicsemi Nrf52840 Firmware up to and including version 2021-03-29.
An adversary can exploit CVE-2021-29415 to recover the private ECC key used during an ECDSA operation.
Please refer to the references provided for information on any available fixes for CVE-2021-29415.