CVE Feed

    Dashboard / CVE / CVE-2021-3011

    CVE-2021-3011

    An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was demonstrated on the Google Titan Security Key, based on an NXP A7005a chip. Other FIDO U2F security keys are also impacted (Yubico YubiKey Neo and Feitian K9, K13, K21, and K40) as well as several NXP JavaCard smartcards (J3A081, J2A081, J3A041, J3D145_M59, J2D145_M59, J3D120_M60, J3D082_M60, J2D120_M60, J2D082_M60, J3D081_M59, J2D081_M59, J3D081_M61, J2D081_M61, J3D081_M59_DF, J3D081_M61_DF, J3E081_M64, J3E081_M66, J2E081_M64, J3E041_M66, J3E016_M66, J3E016_M64, J3E041_M64, J3E145_M64, J3E120_M65, J3E082_M65, J2E145_M64, J2E120_M65, J2E082_M65, J3E081_M64_DF, J3E081_M66_DF, J3E041_M66_DF, J3E016_M66_DF, J3E041_M64_DF, and J3E016_M64_DF).

    Published:Jan 7, 2021
    Last Modified:Nov 21, 2024
    EPS:Jan 7, 2021
    EPSS Score:0.00056
    CVSS Score:4.2

    Affected Products

    Vendor
    Ftsafe
    Product
    K13
    Vendor
    Ftsafe
    Product
    K21
    Vendor
    Ftsafe
    Product
    K40
    Vendor
    Ftsafe
    Product
    K9
    Vendor
    Google
    Product
    Titan Security Key
    Vendor
    Nxp
    Product
    3a081
    Vendor
    Nxp
    Product
    A7005a
    Vendor
    Nxp
    Product
    J2a081
    Vendor
    Nxp
    Product
    J2d081 M59
    Vendor
    Nxp
    Product
    J2d081 M61
    Vendor
    Nxp
    Product
    J2d082 M60
    Vendor
    Nxp
    Product
    J2d120 M60
    Vendor
    Nxp
    Product
    J2d145 M59
    Vendor
    Nxp
    Product
    J2e081 M64
    Vendor
    Nxp
    Product
    J2e082 M65
    Vendor
    Nxp
    Product
    J2e120 M65
    Vendor
    Nxp
    Product
    J2e145 M64
    Vendor
    Nxp
    Product
    J3a041
    Vendor
    Nxp
    Product
    J3d081 M59
    Vendor
    Nxp
    Product
    J3d081 M59 Df
    Vendor
    Nxp
    Product
    J3d081 M61
    Vendor
    Nxp
    Product
    J3d081 M61 Df
    Vendor
    Nxp
    Product
    J3d082 M60
    Vendor
    Nxp
    Product
    J3d120 M60
    Vendor
    Nxp
    Product
    J3d145 M59
    Vendor
    Nxp
    Product
    J3e016 M64
    Vendor
    Nxp
    Product
    J3e016 M64 Df
    Vendor
    Nxp
    Product
    J3e016 M66
    Vendor
    Nxp
    Product
    J3e016 M66 Df
    Vendor
    Nxp
    Product
    J3e041 M64
    Vendor
    Nxp
    Product
    J3e041 M64 Df
    Vendor
    Nxp
    Product
    J3e041 M66
    Vendor
    Nxp
    Product
    J3e041 M66 Df
    Vendor
    Nxp
    Product
    J3e081 M64
    Vendor
    Nxp
    Product
    J3e081 M64 Df
    Vendor
    Nxp
    Product
    J3e081 M66
    Vendor
    Nxp
    Product
    J3e081 M66 Df
    Vendor
    Nxp
    Product
    J3e082 M65
    Vendor
    Nxp
    Product
    J3e120 M65
    Vendor
    Nxp
    Product
    J3e145 M64
    Vendor
    Nxp
    Product
    P5010
    Vendor
    Nxp
    Product
    P5020
    Vendor
    Nxp
    Product
    P5021
    Vendor
    Nxp
    Product
    P5040
    Vendor
    Yubico
    Product
    Yubikey Neo

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High