Improper Certificate Validation in NXP i.MX Series Devices
CVE-2017-7932

6MEDIUM

Key Information:

Vendor

Nxp

Vendor
CVE Published:
7 August 2017

What is CVE-2017-7932?

An improper certificate validation was found in multiple NXP i.MX series devices. This vulnerability arises when devices are configured in a security-enabled configuration. Under specific conditions, it may allow an attacker to bypass signature verification by presenting a specially crafted certificate. This could lead to the execution of unsigned images, posing significant security risks to applications relying on these devices.

Affected Version(s)

NXP i.MX Product Family NXP i.MX Product Family

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.