Boot Loader Vulnerability in Das U-Boot Affecting Multiple Versions
CVE-2021-27097

7.8HIGH

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
17 February 2021

What is CVE-2021-27097?

The boot loader in Das U-Boot prior to version 2021.04-rc2 has a flaw that allows for mishandling of a modified Flattened Image Tree (FIT). This vulnerability may lead to execution of unauthorized commands or the loading of manipulated firmware. Proper validation mechanisms are crucial to prevent potential exploitation in embedded systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.