VulnerabilityModified
CVE-2020-13472
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.
MEDIUM 4.6EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- gigadevice/gd32f103 firmware
- Source
- cve@mitre.org
References
- https://www.usenix.org/system/files/woot20-paper-obermaier.pdfExploit, Technical Description, Third Party Advisory
- https://www.usenix.org/system/files/woot20-paper-obermaier.pdfExploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.