6

CVE-2017-7932

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NxpI.Mx 50 Firmware Version-
   NxpI.Mx 50 Version-
NxpI.Mx 53 Firmware Version-
   NxpI.Mx 53 Version-
NxpI.Mx 6ull Firmware Version-
   NxpI.Mx 6ull Version-
NxpI.Mx 6ultralite Firmware Version-
   NxpI.Mx 6ultralite Version-
NxpI.Mx 6sololite Firmware Version-
   NxpI.Mx 6sololite Version-
NxpI.Mx 6solo Firmware Version-
   NxpI.Mx 6solo Version-
NxpI.Mx 6duallite Firmware Version-
   NxpI.Mx 6duallite Version-
NxpI.Mx 6solox Firmware Version-
   NxpI.Mx 6solox Version-
NxpI.Mx 6dual Firmware Version-
   NxpI.Mx 6dual Version-
NxpI.Mx 6quad Firmware Version-
   NxpI.Mx 6quad Version-
NxpI.Mx 6quadplus Firmware Version-
   NxpI.Mx 6quadplus Version-
NxpI.Mx 6dualplus Firmware Version-
   NxpI.Mx 6dualplus Version-
NxpI.Mx 28 Firmware Version-
   NxpI.Mx 28 Version-
NxpI.Mx 7dual Firmware Version-
   NxpI.Mx 7dual Version-
NxpI.Mx 7solo Firmware Version-
   NxpI.Mx 7solo Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 0.5 5.5
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.