Loading
Generated remediation guidance and an executive summary. No account required.
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.
Use CWE-203, Pengutronix vendor hub and Barebox product page to widen CVE-2021-37848 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-15938, CVE-2019-15937 and CVE-2020-13910 for nearby disclosures in the same product family.