VDB

CVE-2021-3011

CVE-2021-3011 PUBLISHED CVSS 4.199999809265137 MEDIUM

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was demonstrated on the Google Titan Security Key, based on an NXP A7005a chip. Other FIDO U2F security keys are also impacted (Yubico YubiKey Neo and Feitian K9, K13, K21, and K40) as well as several NXP JavaCard smartcards (J3A081, J2A081, J3A041, J3D145_M59, J2D145_M59, J3D120_M60, J3D082_M60, J2D120_M60, J2D082_M60, J3D081_M59, J2D081_M59, J3D081_M61, J2D081_M61, J3D081_M59_DF, J3D081_M61_DF, J3E081_M64, J3E081_M66, J2E081_M64, J3E041_M66, J3E016_M66, J3E016_M64, J3E041_M64, J3E145_M64, J3E120_M65, J3E082_M65, J2E145_M64, J2E120_M65, J2E082_M65, J3E081_M64_DF, J3E081_M66_DF, J3E041_M66_DF, J3E016_M66_DF, J3E041_M64_DF, and J3E016_M64_DF).

EPSS 0.20% · 9.7th percentile

Risk Scores

CVSS 3.1
4.199999809265137
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.20%
9.7th percentile

Affected Products

VendorProductVersions
nxpj2d081_m61
nxpp5020
nxpj3e082_m65
nxpj3d120_m60
ftsafek40
nxpj3e120_m65
googletitan_security_key
n/an/an/a
nxpj2d145_m59
nxpa7005a
nxpj3d145_m59
nxpj3d082_m60
nxpj2d082_m60
nxpj3e016_m66
nxpj3e145_m64
nxpj3e081_m66_df
nxpj3e041_m64
nxpj3d081_m59
nxpj3e041_m66_df
nxp3a081

…and 26 more

Timeline

  • Jan 7, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›