IoT & Hardware

Hardware / Firmware Exposure

Open Serial debug port Allows Dumping, and re-flashing Firmware in Fastrack reflex 2.0 activity tracker

Open Serial debug port Allows Dumping, and re- flashing Firmware It was identified in analyzing the PCB, that the SWD (Serial Wire Debug) the port was open and it gives access to the dumping and…

8.1
/ 10
High
CVSS v3.1
ADVISORY ID
PS50
PUBLISHED
2022-10-04
CVE IDs
CVE-2021-35954
VENDORS
Fastrack
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Fastrack Reflex 2.0 Activity Tracker
CVSS VECTOR
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Open Serial debug port Allows Dumping, and re- flashing Firmware

It was identified in analyzing the PCB, that the SWD (Serial Wire Debug) the port was open and it gives access to the dumping and re-flashing the firmware. an attacker can dump the firmware and flash custom malicious firmware and brick the device.

Vulnerability details

Vulnerability details

CVE-2021-35954
High | 8.1

Open Serial debug port Allows Dumping, and re- flashing Firmware It was identified in analyzing the PCB, that the SWD (Serial Wire Debug) the port was open and it gives access to the dumping and re-flashing the firmware.

Impact:
Arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2020-11-17 reported to the vendor

2021-06-30 No response from the vendor and moving forward to public disclosure.

Credits

Shakir Zari