This vulnerability occurs when a hardware device lacks sufficient shielding against electromagnetic interference, allowing attackers to disrupt its internal operations. By inducing targeted electromagnetic pulses, an attacker can force the device to malfunction, potentially bypassing security checks or leaking sensitive data.
Electromagnetic Fault Injection (EM-FI) is a physical attack where an attacker uses a controlled electromagnetic pulse near a device's integrated circuit. This pulse induces unexpected currents in the chip's wiring, temporarily disrupting normal execution. This manipulation can force the hardware into an erroneous state, allowing an attacker to influence its behavior during critical security operations. Successful EM-FI attacks can have severe consequences, including bypassing secure boot or debug locks, altering program execution to skip authentication, leaking cryptographic keys or other secrets from memory, and corrupting the output of security-critical components like hardware random number generators. These faults are highly localized and precise, often requiring specialized equipment but posing a significant threat to devices accessible to an attacker with physical access.
Impact: Modify MemoryRead MemoryGain Privileges or Assume IdentityBypass Protection MechanismExecute Unauthorized Code or Commands