CVE-2020-11684
Published Sep 14, 2020AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploi…
Vendor/product archive
2 CVEs tagged to linux4sam / at91bootstrap — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploi…
A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code…