CVE-2018-1000205: Input Validation
Published Jun 26, 2018
·Updated
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
Affected Software
1 affected component
DENX U-Boot<=2018.07
Remediation
Patch Available
Event History
Jun 26, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this U-Boot vulnerability?
The vulnerability ID for this U-Boot vulnerability is CVE-2018-1000205.
2
What is the severity of CVE-2018-1000205?
The severity of CVE-2018-1000205 is medium with a CVSS score of 5.5.
3
What is the description of CVE-2018-1000205?
CVE-2018-1000205 is an Improper Input Validation vulnerability in U-Boot that allows bypassing verified boot.
4
How is CVE-2018-1000205 exploited?
CVE-2018-1000205 can be exploited using specially crafted FIT image and special device memory functionality.
5
Is there a fix available for CVE-2018-1000205?
Yes, a fix is available for CVE-2018-1000205 in U-Boot version 2018.07.