Closed
Description
Since the comparison function of the secret for OTA authentication is not constant-time, it is possible for an attacker to discover the OTA secret over the network and flash whatever firmware they like.
The following article has an explanation and fix:
http://blog.ircmaxell.com/2014/11/its-all-about-time.html
Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.