PT-2017-18006 · Nxp · Nxp I.Mx 6Solo+16

Published

2017-08-07

·

Updated

2025-05-13

·

CVE-2017-7932

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NXP i.MX 28 NXP i.MX 50 NXP i.MX 53 NXP i.MX 7Solo NXP i.MX 7Dual NXP Vybrid VF3xx NXP Vybrid VF5xx NXP Vybrid VF6xx NXP i.MX 6ULL NXP i.MX 6UltraLite NXP i.MX 6SoloLite NXP i.MX 6Solo NXP i.MX 6DualLite NXP i.MX 6SoloX NXP i.MX 6Dual NXP i.MX 6Quad NXP i.MX 6DualPlus NXP i.MX 6QuadPlus
Description An issue with improper certificate validation was found. When the device is set up with security enabled, it is possible to bypass signature verification using a specially crafted certificate. This could lead to the execution of an unsigned image under certain conditions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2017-7932

Affected Products

Nxp Vybrid Vf3Xx
Nxp Vybrid Vf5Xx
Nxp Vybrid Vf6Xx
Nxp I.Mx 28
Nxp I.Mx 50
Nxp I.Mx 53
Nxp I.Mx 6Dual
Nxp I.Mx 6Duallite
Nxp I.Mx 6Dualplus
Nxp I.Mx 6Quad
Nxp I.Mx 6Quadplus
Nxp I.Mx 6Solo
Nxp I.Mx 6Sololite
Nxp I.Mx 6Ull
Nxp I.Mx 6Ultralite
Nxp I.Mx 7Dual
Nxp I.Mx 7Solo