CVE-2020-27208 affects SoloKeys Solo 4.0.0 & Somu and Nitrokey FIDO2 tokens, allowing an attacker to downgrade flash read-out protection during device initialization. This physical attack vector (AV:P) has low complexity (AC:L) and can lead to the compromise of sensitive data, including private ECC keys, from SRAM via the debug interface, resulting in high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). Despite its potential severity (CVSS 6.8 MEDIUM), there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:solokeys:solo_firmware:4.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:solokeys:somu_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:nitrokey:fido2_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.