PT-2022-16284 · Xilinx · Xilinx Zynq-7000 Soc

Published

2022-04-27

·

Updated

2022-05-09

·

CVE-2022-23822

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xilinx Zynq-7000 SoC (affected versions not specified)
Description The issue concerns a physical attack where an attacker can potentially exploit the First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This could allow the attacker to perform additional attacks, such as using the device as a decryption oracle.
Recommendations For all affected versions, apply the anticipated 2022.1 patch to resolve the issue. As a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23822

Affected Products

Xilinx Zynq-7000 Soc