Vulnerability Name: CVE-2017-7932 (CCN-129323) Assigned: 2017-07-25 Published: 2017-07-25 Updated: 2019-10-09 Summary: An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image. CVSS v3 Severity: 6.0 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H )5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): PhysicalAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): HighAvailibility (A): High
6.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H )5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): PhysicalAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
5.9 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): HighAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-295 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2017-7932 Source: BID Type: Third Party Advisory, VDB Entry99966 Source: CCN Type: BID-99966Multiple i.MX Products Multiple Local Security Vulnerabilities Source: CCN Type: NXP Web siteNXP i.MX & Vybrid Security Vulnerability Errata Source: XF Type: UNKNOWNnxp-imx-cve20177932-sec-bypass(129323) Source: CCN Type: ICSA-17-152-02NXP i.MX Product Family Source: MISC Type: Third Party Advisory, US Government Resource, VDB Entryhttps://ics-cert.us-cert.gov/advisories/ICSA-17-152-02 Vulnerable Configuration: Configuration 1 :cpe:/o:nxp:vybrid_mvf30nn151cku26_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf30nn151cku26:-:*:*:*:*:*:*:* Configuration 2 :cpe:/o:nxp:vybrid_mvf30ns151cku26_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf30ns151cku26:-:*:*:*:*:*:*:* Configuration 3 :cpe:/o:nxp:vybrid_mvf50nn151cmk40_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf50nn151cmk40:-:*:*:*:*:*:*:* Configuration 4 :cpe:/o:nxp:vybrid_mvf50nn151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf50nn151cmk50:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:nxp:vybrid_mvf50ns151cmk40_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf50ns151cmk40:-:*:*:*:*:*:*:* Configuration 6 :cpe:/o:nxp:vybrid_mvf50ns151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf50ns151cmk50:-:*:*:*:*:*:*:* Configuration 7 :cpe:/o:nxp:vybrid_mvf51nn151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf51nn151cmk50:-:*:*:*:*:*:*:* Configuration 8 :cpe:/o:nxp:vybrid_mvf51ns151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf51ns151cmk50:-:*:*:*:*:*:*:* Configuration 9 :cpe:/o:nxp:vybrid_mvf60nn151cmk40_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf60nn151cmk40:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:nxp:vybrid_mvf60ns151cmk40_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf60ns151cmk40:-:*:*:*:*:*:*:* Configuration 11 :cpe:/o:nxp:vybrid_mvf60nn151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf60nn151cmk50:-:*:*:*:*:*:*:* Configuration 12 :cpe:/o:nxp:vybrid_mvf60ns151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf60ns151cmk50:-:*:*:*:*:*:*:* Configuration 13 :cpe:/o:nxp:vybrid_mvf61nn151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf61nn151cmk50:-:*:*:*:*:*:*:* Configuration 14 :cpe:/o:nxp:vybrid_mvf61ns151cmk50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf61ns151cmk50:-:*:*:*:*:*:*:* Configuration 15 :cpe:/o:nxp:vybrid_mvf62nn151cmk40_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:vybrid_mvf62nn151cmk40:-:*:*:*:*:*:*:* Configuration 16 :cpe:/o:nxp:i.mx_50_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_50:-:*:*:*:*:*:*:* Configuration 17 :cpe:/o:nxp:i.mx_53_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_53:-:*:*:*:*:*:*:* Configuration 18 :cpe:/o:nxp:i.mx_6ull_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6ull:-:*:*:*:*:*:*:* Configuration 19 :cpe:/o:nxp:i.mx_6ultralite_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6ultralite:-:*:*:*:*:*:*:* Configuration 20 :cpe:/o:nxp:i.mx_6sololite_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6sololite:-:*:*:*:*:*:*:* Configuration 21 :cpe:/o:nxp:i.mx_6solo_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6solo:-:*:*:*:*:*:*:* Configuration 22 :cpe:/o:nxp:i.mx_6duallite_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6duallite:-:*:*:*:*:*:*:* Configuration 23 :cpe:/o:nxp:i.mx_6solox_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6solox:-:*:*:*:*:*:*:* Configuration 24 :cpe:/o:nxp:i.mx_6dual_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6dual:-:*:*:*:*:*:*:* Configuration 25 :cpe:/o:nxp:i.mx_6quad_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6quad:-:*:*:*:*:*:*:* Configuration 26 :cpe:/o:nxp:i.mx_6quadplus_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6quadplus:-:*:*:*:*:*:*:* Configuration 27 :cpe:/o:nxp:i.mx_6dualplus_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_6dualplus:-:*:*:*:*:*:*:* Configuration 28 :cpe:/o:nxp:i.mx_28_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_28:-:*:*:*:*:*:*:* Configuration 29 :cpe:/o:nxp:i.mx_7dual_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_7dual:-:*:*:*:*:*:*:* Configuration 30 :cpe:/o:nxp:i.mx_7solo_firmware:-:*:*:*:*:*:*:* AND cpe:/h:nxp:i.mx_7solo:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/h:nxp:i.mx_50:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_53:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6ull:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6ultralite:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6sololite:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6solo:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6duallite:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6solox:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6dual:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6quad:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6dualplus:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_6quadplus:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_28:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_7solo:-:*:*:*:*:*:*:* OR cpe:/h:nxp:i.mx_7dual:-:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
nxp vybrid mvf30nn151cku26 firmware -
nxp vybrid mvf30nn151cku26 -
nxp vybrid mvf30ns151cku26 firmware -
nxp vybrid mvf30ns151cku26 -
nxp vybrid mvf50nn151cmk40 firmware -
nxp vybrid mvf50nn151cmk40 -
nxp vybrid mvf50nn151cmk50 firmware -
nxp vybrid mvf50nn151cmk50 -
nxp vybrid mvf50ns151cmk40 firmware -
nxp vybrid mvf50ns151cmk40 -
nxp vybrid mvf50ns151cmk50 firmware -
nxp vybrid mvf50ns151cmk50 -
nxp vybrid mvf51nn151cmk50 firmware -
nxp vybrid mvf51nn151cmk50 -
nxp vybrid mvf51ns151cmk50 firmware -
nxp vybrid mvf51ns151cmk50 -
nxp vybrid mvf60nn151cmk40 firmware -
nxp vybrid mvf60nn151cmk40 -
nxp vybrid mvf60ns151cmk40 firmware -
nxp vybrid mvf60ns151cmk40 -
nxp vybrid mvf60nn151cmk50 firmware -
nxp vybrid mvf60nn151cmk50 -
nxp vybrid mvf60ns151cmk50 firmware -
nxp vybrid mvf60ns151cmk50 -
nxp vybrid mvf61nn151cmk50 firmware -
nxp vybrid mvf61nn151cmk50 -
nxp vybrid mvf61ns151cmk50 firmware -
nxp vybrid mvf61ns151cmk50 -
nxp vybrid mvf62nn151cmk40 firmware -
nxp vybrid mvf62nn151cmk40 -
nxp i.mx 50 firmware -
nxp i.mx 50 -
nxp i.mx 53 firmware -
nxp i.mx 53 -
nxp i.mx 6ull firmware -
nxp i.mx 6ull -
nxp i.mx 6ultralite firmware -
nxp i.mx 6ultralite -
nxp i.mx 6sololite firmware -
nxp i.mx 6sololite -
nxp i.mx 6solo firmware -
nxp i.mx 6solo -
nxp i.mx 6duallite firmware -
nxp i.mx 6duallite -
nxp i.mx 6solox firmware -
nxp i.mx 6solox -
nxp i.mx 6dual firmware -
nxp i.mx 6dual -
nxp i.mx 6quad firmware -
nxp i.mx 6quad -
nxp i.mx 6quadplus firmware -
nxp i.mx 6quadplus -
nxp i.mx 6dualplus firmware -
nxp i.mx 6dualplus -
nxp i.mx 28 firmware -
nxp i.mx 28 -
nxp i.mx 7dual firmware -
nxp i.mx 7dual -
nxp i.mx 7solo firmware -
nxp i.mx 7solo -
nxp i.mx 50 -
nxp i.mx 53 -
nxp i.mx 6ull -
nxp i.mx 6ultralite -
nxp i.mx 6sololite -
nxp i.mx 6solo -
nxp i.mx 6duallite -
nxp i.mx 6solox -
nxp i.mx 6dual -
nxp i.mx 6quad -
nxp i.mx 6dualplus -
nxp i.mx 6quadplus -
nxp i.mx 28 -
nxp i.mx 7solo -
nxp i.mx 7dual -