The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
History

Tue, 18 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Tue, 11 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 09:30:00 +0000

Type Values Removed Values Added
Description The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
Title Unprotected JTAG Interface
Weaknesses CWE-1191
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-02-18T17:51:43.084Z

Reserved: 2025-02-10T07:48:38.352Z

Link: CVE-2025-26408

cve-icon Vulnrichment

Updated: 2025-02-11T14:41:59.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T10:15:09.617

Modified: 2025-02-18T18:15:36.097

Link: CVE-2025-26408

cve-icon Redhat

No data.