Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-734j-8w33-h29h

Опубликовано: 28 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.

In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.

EPSS

Процентиль: 20%
0.00065
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.8
nvd
почти 4 года назад

In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.

EPSS

Процентиль: 20%
0.00065
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863