CVE-2018-3968

HIGH

U-Boot 2013.07-2014.07 - Cryptographic Signature Verification Bypass via Legacy Image Format

Title source: llm
STIX 2.1

Description

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0633

Scores

CVSS v3 7.0
EPSS 0.0028
EPSS Percentile 19.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (3)
denx/u-boot 2013.07 rc1 (3 CPE variants)
denx/u-boot 2014.07 rc1 (2 CPE variants)
denx/u-boot 2013.07 - 2014.07
Published Mar 21, 2019
Tracked Since Feb 18, 2026