PT-2025-9109 · Minut · Minut M2
Troed Sã¥Ngberg
·
Published
2025-02-28
·
Updated
2025-02-28
·
CVE-2024-44754
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Minut M2 version #15142
Description
The issue allows physically proximate attackers to extract cryptographic keys from the internal flash of Minut M2 devices with the specified firmware version. This can be used to inject modified firmware into other Minut M2 products via USB.
Recommendations
For Minut M2 version #15142, consider restricting physical access to the device and avoiding the use of USB connections from untrusted sources until a fix is available. As a temporary workaround, restrict access to the device's internal flash to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minut M2