PT-2025-9109 · Minut · Minut M2

Troed Sã¥Ngberg

·

Published

2025-02-28

·

Updated

2025-02-28

·

CVE-2024-44754

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Minut M2 version #15142
Description The issue allows physically proximate attackers to extract cryptographic keys from the internal flash of Minut M2 devices with the specified firmware version. This can be used to inject modified firmware into other Minut M2 products via USB.
Recommendations For Minut M2 version #15142, consider restricting physical access to the device and avoiding the use of USB connections from untrusted sources until a fix is available. As a temporary workaround, restrict access to the device's internal flash to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-44754

Affected Products

Minut M2