PT-2024-40 · Gigadevice · Gd32F20X+7
Published
2024-04-12
·
Updated
2024-04-12
CVSS v4.0
7.0
High
| Vector | AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GigaDevice GD32E23x versions
GigaDevice GD32F20x versions
GigaDevice GD32F1x0 versions
GigaDevice GD32F4xx versions
GigaDevice GD32F30x versions
GigaDevice GD32C10x versions
GigaDevice GD32E10x versions
GigaDevice GD32E50x versions
Description
The issue is related to insufficient access control in the GigaDevice microcontroller firmware, which can be exploited to execute arbitrary shell code in SRAM.
Recommendations
For GigaDevice GD32E23x, consider implementing additional access control mechanisms to prevent exploitation.
For GigaDevice GD32F20x, restrict access to sensitive areas of the microcontroller to minimize the risk of exploitation.
For GigaDevice GD32F1x0, apply configuration changes to enhance security and limit the potential for arbitrary code execution.
For GigaDevice GD32F4xx, disable any unnecessary features that could be used to exploit the insufficient access control.
For GigaDevice GD32F30x, implement a workaround to restrict access to the SRAM and prevent shell code execution.
For GigaDevice GD32C10x, consider temporarily disabling the microcontroller until a patch or fix is available.
For GigaDevice GD32E10x, apply a mitigation measure to limit the access to the vulnerable component.
For GigaDevice GD32E50x, avoid using the vulnerable function until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gd32C10X
Gd32E10X
Gd32E23X
Gd32E50X
Gd32F1X0
Gd32F20X
Gd32F30X
Gd32F4Xx