CVE-2024-44754
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-44754 is a vulnerability affecting the Minut M2 device with firmware version #15142. This issue enables physically proximate attackers to extract cryptographic keys from the internal flash of the Minut M2. Consequently, attackers can inject modified firmware into any other Minut M2 product via USB. This vulnerability poses a significant risk as it allows unauthorized access to the affected device, potentially leading to data theft or unauthorized control. Attackers can exploit this issue even without authentication, making it critical for users to update their Minut M2 firmware to the latest version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- M+2