STM32G0 RDP Level 1 Bypass

Does anyone know is RDP level 1 bypass is possible with STM32G0? I’m been following this post Glitching STM32 Read Out Protection - Anvil Secure

It seems my MCU doesn’t have a VCAP pin, which is a 1.something V line right to the core, this might be why my attack isn’t working.

I’m using a Chipwhisperer Husky + crowbar attack.

I have no experience with the STM32G0 but I see it has internal regulators; this presents a challenge to side-channel measurements and voltage glitching. See this note to understand what this means: Targets with Internal Regulators — ChipWhisperer Documentation

Thanks for the doc, sadly it isn’t much help because I don’t have access to the internal regulators output rail.

Is it possible to glitch the GND?

No, the only voltage glitching that Husky (and all other ChipWhisperer devices) can do is the crowbar glitch.

I’m not saying that it’s the only way (or that crowbar glitching cannot work here) but the advantage of EMFI glitching is that it can succeed against targets for which clock and voltage glitching is less feasible.

You can mux with the Husky if you use the 3.3v/Glitch out wired to a multiplexer