CVE Feed

    Dashboard / CVE / CVE-2020-14474

    CVE-2020-14474

    The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption process, and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for every device running the same version of the software, and does not appear to be changed with each new build. It is possible to reconstruct the decryption process using the hardcoded key material and obtain easy access to otherwise protected data.

    Published:Jun 30, 2020
    Last Modified:Nov 21, 2024
    EPS:Jun 30, 2020
    EPSS Score:0.01423
    CVSS Score:7.5

    Affected Products

    Vendor
    Cellebrite
    Product
    Ufed
    Vendor
    Cellebrite
    Product
    Ufed Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High