LiveActive security incident?Get immediate response
CVE Record

CVE-2020-27208: The flash read-out protection (RDP) level is not enforced during the device initialization phase of the Sol...

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This flaw affects specific open-source FIDO security tokens where flash read-out protection was not enforced during device initialization. An attacker with access to the token and debug interface could downgrade protection and read secrets such as private ECC keys from SRAM, undermining the token’s trust role.

Executive priority

Treat this as high priority where affected FIDO2 tokens protect administrators, executives, production systems, or regulated data. For environments without these devices, the issue is informational. The business concern is loss of confidence in hardware-backed authentication if private keys were exposed.

Technical view

CVE-2020-27208 describes an initialization-phase weakness in SoloKeys Solo 4.0.0, Somu, and Nitrokey FIDO2 tokens. Flash RDP is not enforced early enough, allowing an adversary to lower RDP and access SRAM-resident secrets through the debug interface. The bundle does not provide CVSS, CWE, or confirmed exploit-in-the-wild evidence.

Likely exposure

Exposure is limited to organizations using the named hardware tokens, especially for privileged users. Practical risk depends on physical possession or debug-interface access, firmware state, and whether secrets generated or held by affected devices remain trusted.

Exploitation context

The provided sources do not show CISA KEV listing or active exploitation. The attack context is device-level: an adversary must interact with initialization behavior and the debug interface to recover secrets, making this most relevant to targeted physical or supply-chain scenarios.

Researcher notes

Evidence is strongest for the vulnerability mechanism and affected token families listed in the CVE description. The source bundle does not provide exploit prevalence, full remediation matrix, CVSS scoring, or all firmware version boundaries. Avoid extending impact beyond the named devices without vendor confirmation.

Mitigation direction

  • Inventory SoloKeys Solo 4.0.0, Somu, and Nitrokey FIDO2 token deployments.
  • Check vendor guidance and referenced firmware changes before assuming a specific fixed version.
  • Update or replace affected tokens where vendor-supported remediation exists.
  • Re-enroll credentials and rotate associated secrets if token compromise is plausible.
  • Restrict physical custody and debug access for security-token inventories.

Validation and detection

  • Confirm whether affected token models are used for privileged or sensitive accounts.
  • Record firmware versions and compare them against vendor guidance.
  • Review authentication-token enrollment records for users assigned affected devices.
  • Assess whether any tokens had untrusted physical custody or supply-chain exposure.
  • Verify replacement or re-enrollment completed for high-risk accounts.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-27208 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
7Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.