CVE-2020-27211
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2021
Last modified:
03/05/2022
Description
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:nordicsemi:nrf52840_firmware:*:*:*:*:*:*:*:* | 2020-10-19 (including) | |
| cpe:2.3:h:nordicsemi:nrf52840:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://eprint.iacr.org/2021/640
- https://infocenter.nordicsemi.com/pdf/in_133_v1.0.pdf
- https://limitedresults.com/2020/06/nrf52-debug-resurrection-approtect-bypass/
- https://www.aisec.fraunhofer.de/de/das-institut/wissenschaftliche-exzellenz/security-and-trust-in-open-source-security-tokens.html
- https://www.aisec.fraunhofer.de/en/FirmwareProtection.html



