CVE-2024-4760
Voltage glitch during startup of the EEFC NVM controller can bypass the security bit
Severity Score
6.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.
*Credits:
Waleed Alzamil, Bandar Alharbi, Meshari Alhammadi
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-05-10 CVE Reserved
- 2024-05-16 CVE Published
- 2024-05-17 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1247: Improper Protection Against Voltage and Clock Glitches
CAPEC
- CAPEC-624: Hardware Fault Injection
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.0x01team.com/hw_security/bypassing-microchip-atmel-sam-e70-s70-v70-v71-security | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microchip Search vendor "Microchip" | SAME70 Search vendor "Microchip" for product "SAME70" | 0 Search vendor "Microchip" for product "SAME70" and version "0" | en |
Affected
| ||||||
Microchip Search vendor "Microchip" | SAMS70 Search vendor "Microchip" for product "SAMS70" | 0 Search vendor "Microchip" for product "SAMS70" and version "0" | en |
Affected
| ||||||
Microchip Search vendor "Microchip" | SAMV70 Search vendor "Microchip" for product "SAMV70" | 0 Search vendor "Microchip" for product "SAMV70" and version "0" | en |
Affected
| ||||||
Microchip Search vendor "Microchip" | SAMV71 Search vendor "Microchip" for product "SAMV71" | 0 Search vendor "Microchip" for product "SAMV71" and version "0" | en |
Affected
|