CVE-2017-7932: Medium severity nxp vybrid mvf30nn151cku26 vulnerability
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7932?
CVE-2017-7932 has been classified as a high-severity vulnerability due to improper certificate validation.
How do I fix CVE-2017-7932?
To fix CVE-2017-7932, ensure that proper certificate validation methods are implemented in the affected firmware.
Which devices are affected by CVE-2017-7932?
CVE-2017-7932 affects various NXP i.MX and Vybrid devices including i.MX 28, i.MX 50, i.MX 53, and others.
What are the risks associated with CVE-2017-7932?
The risks associated with CVE-2017-7932 include potential exposure to man-in-the-middle attacks due to improper certificate validation.
Is there a patch for CVE-2017-7932?
As of now, users should check with NXP for any available patches addressing CVE-2017-7932 for their specific hardware.