VendorsLinux4SAMat91bootstrapall versions
Vulnerabilities

Linux4SAM AT91Bootstrap

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-11684
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).
Published 2020-09-14 · Modified
9.1EPSS 0.011
CVE-2020-11683
A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected system.
Published 2020-09-14 · Modified
6.8EPSS 0.005