CVE-2020-25082: Low severity nuvoton npct75x firmware vulnerability
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25082?
CVE-2020-25082 is rated as a medium-severity vulnerability due to its requirement for physical access to exploit the flaw.
How do I fix CVE-2020-25082?
To mitigate CVE-2020-25082, upgrade the Nuvoton NPCT75x firmware to version 7.2.2.0 or later.
What type of attack is associated with CVE-2020-25082?
CVE-2020-25082 is associated with a side-channel attack that targets the timing discrepancies in the ECDSA implementation.
Which devices are affected by CVE-2020-25082?
CVE-2020-25082 affects Nuvoton NPCT75x firmware versions from 7.2.0 to 7.2.1.0.
Can CVE-2020-25082 be exploited remotely?
No, CVE-2020-25082 requires an attacker to have physical access to the device to exploit the vulnerability.