CVE-2024-4760

Published at:
2024-05-16T13:15:47.893
Source: dc3f6da9-85b5-4a73-84a2-2ec90b40fca5

Global infos:

A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.

CVE Status: Awaiting Analysis

References:

  • dc3f6da9-85b5-4a73-84a2-2ec90b40fca5
  • af854a3a-2127-422b-91ae-364da2661108
  • Metrics:

    AttributeValue
    Attack ComplexityHIGH
    Attack VectorPHYSICAL
    Availability ImpactHIGH
    Base Score6.3
    Base SeverityMEDIUM
    Confidentiality ImpactHIGH
    Integrity ImpactHIGH
    Privileges RequiredNONE
    ScopeUNCHANGED
    User InteractionREQUIRED
    Vector StringCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
    Exploitability Score0.4
    Impact Score5.9
    Sourcedc3f6da9-85b5-4a73-84a2-2ec90b40fca5
    TypeSecondary

    Links:

    Exploit-db
    Github