Insecure Storage of Sensitive Information
CVE-2020-10368
Summary
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.
- LOW
- ADJACENT_NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-922 - Insecure Storage of Sensitive Information
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
References
Advisory Timeline
- Published