5.5

CVE-2019-5478

A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AmdZu11eg Firmware Version-
   AmdZu11eg Version-
AmdZu15eg Firmware Version-
   AmdZu15eg Version-
AmdZu17eg Firmware Version-
   AmdZu17eg Version-
AmdZu19eg Firmware Version-
   AmdZu19eg Version-
AmdZu1cg Firmware Version-
   AmdZu1cg Version-
AmdZu1eg Firmware Version-
   AmdZu1eg Version-
AmdZu21dr Firmware Version-
   AmdZu21dr Version-
AmdZu25dr Firmware Version-
   AmdZu25dr Version-
AmdZu27dr Firmware Version-
   AmdZu27dr Version-
AmdZu28dr Firmware Version-
   AmdZu28dr Version-
AmdZu29dr Firmware Version-
   AmdZu29dr Version-
AmdZu2cg Firmware Version-
   AmdZu2cg Version-
AmdZu2eg Firmware Version-
   AmdZu2eg Version-
AmdZu39dr Firmware Version-
   AmdZu39dr Version-
AmdZu3cg Firmware Version-
   AmdZu3cg Version-
AmdZu3eg Firmware Version-
   AmdZu3eg Version-
AmdZu3tcg Firmware Version-
   AmdZu3tcg Version-
AmdZu3teg Firmware Version-
   AmdZu3teg Version-
AmdZu42dr Firmware Version-
   AmdZu42dr Version-
AmdZu43dr Firmware Version-
   AmdZu43dr Version-
AmdZu46dr Firmware Version-
   AmdZu46dr Version-
AmdZu47dr Firmware Version-
   AmdZu47dr Version-
AmdZu48dr Firmware Version-
   AmdZu48dr Version-
AmdZu49dr Firmware Version-
   AmdZu49dr Version-
AmdZu4cg Firmware Version-
   AmdZu4cg Version-
AmdZu4eg Firmware Version-
   AmdZu4eg Version-
AmdZu4ev Firmware Version-
   AmdZu4ev Version-
AmdZu5cg Firmware Version-
   AmdZu5cg Version-
AmdZu5eg Firmware Version-
   AmdZu5eg Version-
AmdZu5ev Firmware Version-
   AmdZu5ev Version-
AmdZu63dr Firmware Version-
   AmdZu63dr Version-
AmdZu64dr Firmware Version-
   AmdZu64dr Version-
AmdZu65dr Firmware Version-
   AmdZu65dr Version-
AmdZu67dr Firmware Version-
   AmdZu67dr Version-
AmdZu6cg Firmware Version-
   AmdZu6cg Version-
AmdZu6eg Firmware Version-
   AmdZu6eg Version-
AmdZu7cg Firmware Version-
   AmdZu7cg Version-
AmdZu7eg Firmware Version-
   AmdZu7eg Version-
AmdZu7ev Firmware Version-
   AmdZu7ev Version-
AmdZu9cg Firmware Version-
   AmdZu9cg Version-
AmdZu9eg Firmware Version-
   AmdZu9eg Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-657 Violation of Secure Design Principles

The product violates well-established principles for secure design.