Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-27208

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.9%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.6
Products affected by CVE-2020-27208


Contact Us

Shodan ® - All rights reserved