Nordic Semiconductor nRF52810 On-Chip Debug Interface Improper Access Control Vulnerability Allowing Electromagnetic Fault Injection

Vulnerability

A vulnerability in the on-chip debug and test interface of Nordic Semiconductor nRF52810 devices, prior to 2020-10-19, has been identified. This vulnerability arises from improper access control and inadequate protection against electromagnetic fault injection (EM-FI). Exploitation of this vulnerability allows an attacker to perform EM fault injection, bypassing the flash read-out protection (APPROTECT) during runtime with minimal hardware modification.

Impact

Exploitation of this vulnerability allows for electromagnetic fault injection that can corrupt instructions, bypassing software-based countermeasures and gaining control over the program counter, leading to arbitrary code execution. This has been demonstrated on the ARM32 architecture, including on devices running Linux.

Reproduction

The vulnerability can be reproduced by injecting electromagnetic faults into the nRF52810 chip's debug interface while the device is powered on. This can be done using specialized equipment that generates electromagnetic signals, targeting the chip's response to normal operational commands. The injected faults can disrupt the execution of instructions, particularly during data transfers that are under the attacker's control, such as via the USB interface. This manipulation can be timed to hijack the program counter, redirecting execution to arbitrary code.

Added: Sep 5, 2025, 7:24 PM
Updated: Sep 5, 2025, 7:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.6
remediation
0.0
relevance
0.4
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.