CVE-2017-3226
published 2018-07-24CVE-2017-3226: Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature…
PriorityP424medium6.4CVSS 3.0
AVPACHPRNUINSUCHIHAH
EPSS
0.27%
18.4th percentile
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables from disk as the encrypted disk image is processed. An attacker with physical access to the device can manipulate the encrypted environment data to include a crafted two-byte sequence which triggers an error in environment variable parsing. This error condition is improperly handled by Das U-Boot, resulting in an immediate process termination with a debugging message.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| das | u-boot | >= 2017.09 < 2017.09 | 2017.09 |
| debian | u-boot | — | — |
| denx | u-boot | < 2017.09 | 2017.09 |
CVSS provenance
nvdv3.06.4MEDIUMCVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg74-j96c-c2wj: Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file
ghsa_unreviewed·2022-05-13
CVE-2017-3226 [MEDIUM] GHSA-wg74-j96c-c2wj: Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables from disk as the encrypted disk image is processed. An attacker with physical access to the device can manipulate the encrypted environment data to include a crafted two-byte sequence which triggers an error in environment variable parsing. This error condition is improperly handled by Das U-Boot, resulting in an immediate process termination with a debugging message.
OSV
CVE-2017-3226: Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file
osv·2018-07-24·CVSS 6.4
CVE-2017-3226 [MEDIUM] CVE-2017-3226: Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables from disk as the encrypted disk image is processed. An attacker with physical access to the device can manipulate the encrypted environment data to include a crafted two-byte sequence which triggers an error in environment variable parsing. This error condition is improperly handled by Das U-Boot, resulting in an immediate process termination with a debugging message.
Debian
CVE-2017-3226: u-boot - Das U-Boot is a device bootloader that can read its configuration from an AES en...
vendor_debian·2017·CVSS 6.4
CVE-2017-3226 [MEDIUM] CVE-2017-3226: u-boot - Das U-Boot is a device bootloader that can read its configuration from an AES en...
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables from disk as the encrypted disk image is processed. An attacker with physical access to the device can manipulate the encrypted environment data to include a crafted two-byte sequence which triggers an error in environment variable parsing. This error condition is improperly handled by Das U-Boot, resulting in an immediate process termination with a debugging message.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-24
Published