VulnerabilityAnalyzed
CVE-2019-5478
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.
MEDIUM 5.5EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-657, CWE-345
- Affected
- amd/zu11eg firmware · amd/zu15eg firmware · amd/zu17eg firmware · amd/zu19eg firmware · amd/zu1cg firmware · amd/zu1eg firmware · amd/zu21dr firmware · amd/zu25dr firmware · amd/zu27dr firmware · amd/zu28dr firmware · amd/zu29dr firmware · amd/zu2cg firmware · amd/zu2eg firmware · amd/zu39dr firmware · amd/zu3cg firmware · amd/zu3eg firmware · amd/zu3tcg firmware · amd/zu3teg firmware · amd/zu42dr firmware · amd/zu43dr firmware · +21 more
- Source
- support@hackerone.com
References
- https://github.com/inversepath/advisories/blob/master/Security_Advisory-Ref_FSC-HWSEC-VR2019-0001-Xilinx_ZU+-Encrypt_Only_Secure_Boot_bypass.txtThird Party Advisory
- https://www.xilinx.com/support/answers/72588.htmlVendor Advisory
- https://github.com/inversepath/advisories/blob/master/Security_Advisory-Ref_FSC-HWSEC-VR2019-0001-Xilinx_ZU+-Encrypt_Only_Secure_Boot_bypass.txtThird Party Advisory
- https://www.xilinx.com/support/answers/72588.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.