CVE-2020-27209
Dashboard / Vulnerabilities / CVE-2020-27209
CVE-2020-27209
Published: 20 May 2021Last Modified: 8 Jul 2026
Summary:
Details: The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.
References: https://eprint.iacr.org/2021/640, https://github.com/kmackay/micro-ecc/releases, https://www.aisec.fraunhofer.de/de/das-institut/wissenschaftliche-exzellenz/security-and-trust-in-open-source-security-tokens.html, https://www.aisec.fraunhofer.de/en/FirmwareProtection.html, https://github.com/kmackay/micro-ecc/commit/1b5f5cea5145c96dd8791b9b2c41424fc74c2172
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- d037ec89546fad14b5c4d5456c2e23a71e554966
Fixed -None
Affected versions
1.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
