Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.usenix.org/system/files/woot20-paper-obermaier.pdf | exploit third party advisory technical description |