CVE-2022-0553: Possible to retrieve uncrypted firmware image
Published Jan 11, 2023
·Updated
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.
Affected Software
1 affected component
zephyrproject zephyr<3.0.0
Remediation
Event History
Jan 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-0553.
2
What is the severity of CVE-2022-0553?
The severity of CVE-2022-0553 is medium with a severity value of 4.6.
3
What is affected by CVE-2022-0553?
The Zephyr operating system versions up to 3.0.0 in the Zephyrproject Zephyr software are affected by CVE-2022-0553.
4
What is the impact of CVE-2022-0553?
The impact of CVE-2022-0553 is that unencrypted firmware can be easily retrieved when using encrypted images.
5
How can CVE-2022-0553 be fixed?
To fix CVE-2022-0553, a check should be added to ensure that slot 0 is not being uploaded from the device to the host when using encrypted images.