CVE-2022-23822: Medium severity xilinx zynq-7000 series firmware vulnerability
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23822?
The severity of CVE-2022-23822 is high due to the potential for an attacker to bypass authentication and load malicious firmware.
How do I fix CVE-2022-23822?
To fix CVE-2022-23822, update the Xilinx Zynq-7000 Firmware to version 2022.1 or later.
What devices are affected by CVE-2022-23822?
CVE-2022-23822 affects the Xilinx Zynq-7000 and Zynq-7000s devices' First Stage Boot Loader firmware versions prior to 2022.1.
What type of attack is possible with CVE-2022-23822?
CVE-2022-23822 allows an attacker to execute a physical attack by loading a malicious image onto the device.
Is authentication bypass a concern in CVE-2022-23822?
Yes, CVE-2022-23822 involves an authentication bypass that permits unauthorized access to the device.