PT-2024-40 · Gigadevice · Gd32F20X+7

Published

2024-04-12

·

Updated

2024-04-12

CVSS v4.0

7.0

High

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GigaDevice GD32E23x versions GigaDevice GD32F20x versions GigaDevice GD32F1x0 versions GigaDevice GD32F4xx versions GigaDevice GD32F30x versions GigaDevice GD32C10x versions GigaDevice GD32E10x versions GigaDevice GD32E50x versions
Description The issue is related to insufficient access control in the GigaDevice microcontroller firmware, which can be exploited to execute arbitrary shell code in SRAM.
Recommendations For GigaDevice GD32E23x, consider implementing additional access control mechanisms to prevent exploitation. For GigaDevice GD32F20x, restrict access to sensitive areas of the microcontroller to minimize the risk of exploitation. For GigaDevice GD32F1x0, apply configuration changes to enhance security and limit the potential for arbitrary code execution. For GigaDevice GD32F4xx, disable any unnecessary features that could be used to exploit the insufficient access control. For GigaDevice GD32F30x, implement a workaround to restrict access to the SRAM and prevent shell code execution. For GigaDevice GD32C10x, consider temporarily disabling the microcontroller until a patch or fix is available. For GigaDevice GD32E10x, apply a mitigation measure to limit the access to the vulnerable component. For GigaDevice GD32E50x, avoid using the vulnerable function until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09909

Affected Products

Gd32C10X
Gd32E10X
Gd32E23X
Gd32E50X
Gd32F1X0
Gd32F20X
Gd32F30X
Gd32F4Xx