ORSHIN Attack Defense Framework

Firmware Manipulation via Debug Interface due to I2C Protocol Vulnerability

Description

Firmware Manipulation via Debug Interface due to I2C Protocol Vulnerability

CWE

319

523

CVE

12061

Attack Surfaces

Debug Interface (MITRE EMB3D PID-15)

Bus Interface (MITRE EMB3D PID-13)

Controller Implementation (MITRE EMB3D PID-11)

FW

Authenticated Sessions (MITRE EMB3D PID-3322)

Attack Vectors

Firmware Execution

Firmware Rollback (MITRE EMB3D TID-216)

Insecure Cryptographic Implementation (MITRE EMB3D TID-318)

Defenses

Protect Credential Transmission between Microcontroller and Secure Element, Insource MAC Hash Computation to the Microcontroller