First published: Wed Jan 11 2023(Updated: )
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.
Credit: vulnerabilities@zephyrproject.org vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-0553.
The severity of CVE-2022-0553 is medium with a severity value of 4.6.
The Zephyr operating system versions up to 3.0.0 in the Zephyrproject Zephyr software are affected by CVE-2022-0553.
The impact of CVE-2022-0553 is that unencrypted firmware can be easily retrieved when using encrypted images.
To fix CVE-2022-0553, a check should be added to ensure that slot 0 is not being uploaded from the device to the host when using encrypted images.