The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
Solution:
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
Link | Tags |
---|---|
https://r.sec-consult.com/wattsense | third party advisory |
https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes | release notes |