← Back

Xilinx

xilinx

2 CVEs • 5 products

Products (5)

Click to collapse
Toggle

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xilinx
2Zynq 7000 Firmware
Zynq 7000s Firmware
Nov 21, 2024
Apr 27, 2022
N/A· v4
6.8 MEDIUM· v3
4.4 MEDIUM· v2
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the...Show more
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.Show less
1Xilinx
2Zynq 7000 Firmware
Zynq 7000s Firmware
Nov 21, 2024
Mar 15, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page...Show more
When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could lead to arbitrary code execution. Physical access and modification of the board assembly on which the Zynq-7000 SoC device mounted is needed to replace the original NAND flash memory with a NAND flash emulation device for this attack to be successful.Show less