CVE-2021-3011

Description from NVD

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was demonstrated on the Google Titan Security Key, based on an NXP A7005a chip. Other FIDO U2F security keys are also impacted (Yubico YubiKey Neo and Feitian K9, K13, K21, and K40) as well as several NXP JavaCard smartcards (J3A081, J2A081, J3A041, J3D145_M59, J2D145_M59, J3D120_M60, J3D082_M60, J2D120_M60, J2D082_M60, J3D081_M59, J2D081_M59, J3D081_M61, J2D081_M61, J3D081_M59_DF, J3D081_M61_DF, J3E081_M64, J3E081_M66, J2E081_M64, J3E041_M66, J3E016_M66, J3E016_M64, J3E041_M64, J3E145_M64, J3E120_M65, J3E082_M65, J2E145_M64, J2E120_M65, J2E082_M65, J3E081_M64_DF, J3E081_M66_DF, J3E041_M66_DF, J3E016_M66_DF, J3E041_M64_DF, and J3E016_M64_DF).

Information Acquisition Date:2021-04-27T11:03Z
CVSS 2.0: 1.9 LOW CVSS 3.x: 4.2 MEDIUM

▼ CVSS3 Vec CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

▼ CVSS2 Vec AV:L/AC:M/Au:N/C:P/I:N/A:N

NVD References

 https://ninjalab.io/wp-content/uploads/2021/01/a_side_journey_to_titan.pdf
     source:MISC
     tags:Exploit    Technical Description    Third Party Advisory    
 https://ninjalab.io/a-side-journey-to-titan/
     source:MISC
     tags:Third Party Advisory    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
https://news.ycombinator.com/item?id=256755566
https://twitter.com/nixcraft/status/13474591113282560045
https://ninjalab.io/a-side-journey-to-titan/4
https://thehackernews.com/2021/01/new-attack-could-let-hack...3

Information from Twitter

User URL Info Source Date
infinityABCDE https://ninjalab.io/a-side-journey-to-titan/ Source infinityABCDE    1440111210662400000 2021/09/21
infinityABCDE https://twitter.com/infinityABCDE/status/144011121066240000... Source infinityABCDE    1440111210662400000 2021/09/21

List of frequently cited URLs

URLNum of Times Referred to
news.ycombinator.com6
twitter.com5
ninjalab.io4
thehackernews.com3

Information from Twitter

User URL Info Source
infinityABCDE ninjalab.io Show Tweet
infinityABCDE twitter.com Show Tweet

GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2021/10/28 Score : 1
Added Har-sia Database : 2021/01/08
Last Modified : 2021/10/28
Highest Scored Date : 2021/01/08
Highest Score : 40