SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-5478

A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.

MEDIUM 5.5EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.25% probability · 16th percentile
CISA KEV
Not listed
Weakness
CWE-657, CWE-345
Affected
amd/zu11eg firmware · amd/zu15eg firmware · amd/zu17eg firmware · amd/zu19eg firmware · amd/zu1cg firmware · amd/zu1eg firmware · amd/zu21dr firmware · amd/zu25dr firmware · amd/zu27dr firmware · amd/zu28dr firmware · amd/zu29dr firmware · amd/zu2cg firmware · amd/zu2eg firmware · amd/zu39dr firmware · amd/zu3cg firmware · amd/zu3eg firmware · amd/zu3tcg firmware · amd/zu3teg firmware · amd/zu42dr firmware · amd/zu43dr firmware · +21 more
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.