CVE-2020-11683
Summary
| CVE | CVE-2020-11683 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-14 14:15:00 UTC |
| Updated | 2021-04-08 14:47:00 UTC |
| Description | A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system. |
Risk And Classification
Problem Types: CWE-203
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Linux4sam | At91bootstrap | All | All | All | All |
| Application | Linux4sam | At91bootstrap | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microchip AT91Bootstrap Code Authentication Issues | MISC | labs.f-secure.com | Exploit, Third Party Advisory |
| driver: secure: use consttime_memequal for memory comparison · linux4sam/at91bootstrap@7753914 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.