Electromagnetic Wave Side-Channel Issue on NXP SmartMX and A7x Microcontrollers
CVE-2021-3011

4.2MEDIUM

Key Information:

Vendor

Yubico

Status
Vendor
CVE Published:
7 January 2021

What is CVE-2021-3011?

An electromagnetic-wave side-channel vulnerability exists in NXP SmartMX and A7x microcontrollers, enabling attackers to potentially extract ECDSA private keys through physical access. This serious flaw, demonstrated on devices like the Google Titan Security Key, poses risks to multiple products including various FIDO U2F security keys and NXP JavaCard smartcards. Effective remediation and security measures are essential to protect against potential exploits.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.