CVE-2020-12061
Summary
| CVE | CVE-2020-12061 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-21 12:15:00 UTC |
| Updated | 2022-10-05 16:08:00 UTC |
| Description | An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a result, the attacker is able to arbitrarily manipulate the firmware of the microcontroller. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nitrokey | Fido U2f | - | All | All | All |
| Operating System | Nitrokey | Fido U2f Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases · Nitrokey/nitrokey-fido-u2f-firmware · GitHub | MISC | github.com | |
| CWE - CWE-523: Unprotected Transport of Credentials (4.3) | MISC | cwe.mitre.org | |
| eprint.iacr.org/2021/640.pdf | MISC | eprint.iacr.org | |
| Commits · Nitrokey/nitrokey-fido-u2f-firmware · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.