Versio.io

CVE-2021-44850

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 10-02-2022 08:15
Last modified: - 17-02-2022 06:26
Total changes: - 2

Description

On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that a secure image appears to be unencrypted, and they will be able to modify the full range of register initialization values. Normally, these registers will be restricted when booting securely. Of importance to this attack are two registers that control the SD card's transfer type and transfer size. These registers could be modified a way that causes a buffer overflow in the ROM.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Physical
Attack vector
High
Availability
High
Confidentiality
High
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
6.8
Base score
0.9
5.9
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=amd AND product=xilinx_z-7012s_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7012s AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7014s_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7014s AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7010_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7010 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7015_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7015 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7020_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7020 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7030_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7030 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7035_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7035 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7045_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7045 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7100_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7100 AND version=-
AND
OR
vendor=amd AND product=xilinx_z-7007s_firmware AND version=-
OR
vendor=amd AND product=xilinx_z-7007s AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2021-44850

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.