CVE-2020-11684

AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:linux4sam:at91bootstrap:*:*:*:*:*:*:*:*

Information

Published : 2020-09-14 07:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-11684

Mitre link : CVE-2020-11684


JSON object : View

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

Advertisement

dedicated server usa

Products Affected

linux4sam

  • at91bootstrap