CVE-2019-5478: Medium severity xilinx zynq ultrascale+ mpsoc firmware vulnerability
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5478?
CVE-2019-5478 has been assessed as having a medium severity level due to its potential impact on secure boot functionality.
How do I fix CVE-2019-5478?
To mitigate CVE-2019-5478, ensure you update to the latest firmware provided by Xilinx for Zynq UltraScale+ devices.
What devices are affected by CVE-2019-5478?
CVE-2019-5478 affects Xilinx Zynq UltraScale+ and Zynq UltraScale+ RFSoC devices in Encrypt Only boot mode.
What risks does CVE-2019-5478 pose to my system?
CVE-2019-5478 may allow an adversary to manipulate boot control fields, leading to improper secure boot behavior.
Can CVE-2019-5478 be exploited remotely?
CVE-2019-5478 is not specifically a remote vulnerability, but it can be exploited by physical access to the affected devices.