PT-2017-18006 · Nxp · Nxp I.Mx 6Solo+16
Published
2017-08-07
·
Updated
2025-05-13
·
CVE-2017-7932
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NXP i.MX 28
NXP i.MX 50
NXP i.MX 53
NXP i.MX 7Solo
NXP i.MX 7Dual
NXP Vybrid VF3xx
NXP Vybrid VF5xx
NXP Vybrid VF6xx
NXP i.MX 6ULL
NXP i.MX 6UltraLite
NXP i.MX 6SoloLite
NXP i.MX 6Solo
NXP i.MX 6DualLite
NXP i.MX 6SoloX
NXP i.MX 6Dual
NXP i.MX 6Quad
NXP i.MX 6DualPlus
NXP i.MX 6QuadPlus
Description
An issue with improper certificate validation was found. When the device is set up with security enabled, it is possible to bypass signature verification using a specially crafted certificate. This could lead to the execution of an unsigned image under certain conditions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nxp Vybrid Vf3Xx
Nxp Vybrid Vf5Xx
Nxp Vybrid Vf6Xx
Nxp I.Mx 28
Nxp I.Mx 50
Nxp I.Mx 53
Nxp I.Mx 6Dual
Nxp I.Mx 6Duallite
Nxp I.Mx 6Dualplus
Nxp I.Mx 6Quad
Nxp I.Mx 6Quadplus
Nxp I.Mx 6Solo
Nxp I.Mx 6Sololite
Nxp I.Mx 6Ull
Nxp I.Mx 6Ultralite
Nxp I.Mx 7Dual
Nxp I.Mx 7Solo