ID

VAR-202009-0213


CVE

CVE-2020-12787


TITLE

Microchip Atmel ATSAMA5  Product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2020-011345

DESCRIPTION

Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling. Microchip Atmel ATSAMA5 The product contains unspecified vulnerabilities.Information may be tampered with

Trust: 1.71

sources: NVD: CVE-2020-12787 // JVNDB: JVNDB-2020-011345 // VULMON: CVE-2020-12787

AFFECTED PRODUCTS

vendor:microchipmodel:atsama5d27c-d1g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d42a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d26c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-ld2g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d43b-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d24c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-ld2g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d24c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d42b-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d23c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d35a-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d42a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27-som1scope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d41b-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d33a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d225c-d1m-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d34a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d22c-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d35a-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d41a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d41a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d43a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d43a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d36a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d35a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-d5m-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-cnrvaoscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d31a-cfuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d42b-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d26c-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d22c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-ld2g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d31a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d31a-cfurscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d33a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d41b-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-ld1g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27-wlsom1scope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d34a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d21c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d31a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d44a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-ld1g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d24c-cufscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d26c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d22c-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-ld2g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d35a-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d44b-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-ld1g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d23c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-d5m-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d23c-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d43b-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d36a-cnscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d22c-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-d1g-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d36a-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d44b-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d26c-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-ld1g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d44a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-d1g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d21c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d23c-cnrscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-d1g-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d27c-cnvaoscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d36a-cuscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d28c-curscope:eqversion: -

Trust: 1.0

vendor:microchipmodel:atsama5d21c-curscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d21c-cuscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d22c-cnrscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d22c-cnscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d22c-curscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d22c-cuscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d23c-cnrscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d23c-cnscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d23c-curscope: - version: -

Trust: 0.8

vendor:microchipmodel:atsama5d23c-cuscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-011345 // NVD: CVE-2020-12787

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-12787
value: HIGH

Trust: 1.0

NVD: CVE-2020-12787
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202009-880
value: HIGH

Trust: 0.6

VULMON: CVE-2020-12787
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-12787
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2020-12787
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-12787
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2020-12787 // JVNDB: JVNDB-2020-011345 // CNNVD: CNNVD-202009-880 // NVD: CVE-2020-12787

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-011345 // NVD: CVE-2020-12787

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202009-880

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202009-880

PATCH

title:Top Pageurl:https://www.microchip.com/

Trust: 0.8

title:Microchip Atmel ATSAMA5 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=128571

Trust: 0.6

title:SAMA5D-unlockerurl:https://github.com/Philippe-Gandolfo/SAMA5D-unlocker

Trust: 0.1

title:advisoriesurl:https://github.com/f-secure-foundry/advisories

Trust: 0.1

title:advisoriesurl:https://github.com/inversepath/advisories

Trust: 0.1

sources: VULMON: CVE-2020-12787 // JVNDB: JVNDB-2020-011345 // CNNVD: CNNVD-202009-880

EXTERNAL IDS

db:NVDid:CVE-2020-12787

Trust: 2.5

db:JVNDBid:JVNDB-2020-011345

Trust: 0.8

db:CNNVDid:CNNVD-202009-880

Trust: 0.6

db:VULMONid:CVE-2020-12787

Trust: 0.1

sources: VULMON: CVE-2020-12787 // JVNDB: JVNDB-2020-011345 // CNNVD: CNNVD-202009-880 // NVD: CVE-2020-12787

REFERENCES

url:https://labs.f-secure.com/advisories/microchip-atsama5-soc-multiple-vulnerabilities/

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-12787

Trust: 1.4

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://github.com/philippe-gandolfo/sama5d-unlocker

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2020-12787 // JVNDB: JVNDB-2020-011345 // CNNVD: CNNVD-202009-880 // NVD: CVE-2020-12787

SOURCES

db:VULMONid:CVE-2020-12787
db:JVNDBid:JVNDB-2020-011345
db:CNNVDid:CNNVD-202009-880
db:NVDid:CVE-2020-12787

LAST UPDATE DATE

2024-11-23T22:40:57.886000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-12787date:2020-09-18T00:00:00
db:JVNDBid:JVNDB-2020-011345date:2021-03-29T08:51:00
db:CNNVDid:CNNVD-202009-880date:2020-09-21T00:00:00
db:NVDid:CVE-2020-12787date:2024-11-21T05:00:17.710

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-12787date:2020-09-14T00:00:00
db:JVNDBid:JVNDB-2020-011345date:2021-03-29T00:00:00
db:CNNVDid:CNNVD-202009-880date:2020-09-14T00:00:00
db:NVDid:CVE-2020-12787date:2020-09-14T14:15:10.743