The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/429253/100/0/threaded | mailing list |
http://www.hexview.com/docs/20060328-1.txt | |
http://securityreason.com/securityalert/648 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25527 | vdb entry |