A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element authentication, and then use the secure element as an oracle to decrypt all encrypted update files.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Dec 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element authentication, and then use the secure element as an oracle to decrypt all encrypted update files. | |
Weaknesses | CWE-522 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-12-10T13:54:14.682Z
Updated: 2024-12-10T17:17:37.372Z
Reserved: 2024-11-22T14:39:32.052Z
Link: CVE-2024-53832
Vulnrichment
Updated: 2024-12-10T15:17:07.852Z
NVD
Status : Received
Published: 2024-12-10T14:30:46.853
Modified: 2024-12-10T14:30:46.853
Link: CVE-2024-53832
Redhat
No data.