Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3011

18
FAUCET Score

CVE-2021-3011 describes an electromagnetic-wave side-channel vulnerability in NXP SmartMX/P5x and A7x microcontrollers, impacting various FIDO U2F security keys (including Google Titan, Yubico YubiKey Neo, and Feitian models) and NXP JavaCard smartcards. This flaw allows attackers with extensive physical access to extract ECDSA private keys, potentially leading to device cloning. The vulnerability has a CVSS score of 4.2 (Medium), indicating a physical attack vector with high complexity and high confidentiality impact, but no integrity or availability impact. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:ftsafe:k13:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:ftsafe:k21:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:ftsafe:k40:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:ftsafe:k9:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:google:titan_security_key:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.2MEDIUM

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.5
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 27th percentile among its peer group of 152 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted

Vendor Advisories (6)

capnprotollm-capnproto-ebdf0d91195ad78cLOW

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021
openwrtllm-openwrt-f9a4d28f469a8484MEDIUM

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021
gcpllm-gcp-9cad7522e4541c37MEDIUM

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021
kongllm-kong-2b8574fe3ce01f1eMEDIUM

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021
hanwhallm-hanwha-9c2c5680b83e7a03MEDIUM

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021
proxmoxllm-proxmox-b4852a79b8fb2152MEDIUM

Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders

Mar 3, 2021

References

ninjalab.io / a-side-journey-to-titan
Third Party Advisory
ninjalab.io / wp-content/uploads/2021/01/a_side_journey_to_titan.pdf
ExploitTechnical DescriptionThird Party Advisory