CVE-2019-5478

A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:xilinx:zynq_ultrascale\+_mpsoc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:xilinx:zynq_ultrascale\+_mpsoc:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:xilinx:zynq_ultrascale\+_rfsoc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:xilinx:zynq_ultrascale\+_rfsoc:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:45

Type Values Removed Values Added
References () https://github.com/inversepath/advisories/blob/master/Security_Advisory-Ref_FSC-HWSEC-VR2019-0001-Xilinx_ZU+-Encrypt_Only_Secure_Boot_bypass.txt - Third Party Advisory () https://github.com/inversepath/advisories/blob/master/Security_Advisory-Ref_FSC-HWSEC-VR2019-0001-Xilinx_ZU+-Encrypt_Only_Secure_Boot_bypass.txt - Third Party Advisory
References () https://www.xilinx.com/support/answers/72588.html - Vendor Advisory () https://www.xilinx.com/support/answers/72588.html - Vendor Advisory

Information

Published : 2019-09-03 20:15

Updated : 2024-11-21 04:45


NVD link : CVE-2019-5478

Mitre link : CVE-2019-5478

CVE.ORG link : CVE-2019-5478


JSON object : View

Products Affected

xilinx

  • zynq_ultrascale\+_rfsoc_firmware
  • zynq_ultrascale\+_mpsoc_firmware
  • zynq_ultrascale\+_rfsoc
  • zynq_ultrascale\+_mpsoc
CWE
CWE-657

Violation of Secure Design Principles

CWE-345

Insufficient Verification of Data Authenticity