6
CVSSv3

CVE-2017-7932

Published: 07/08/2017 Updated: 09/10/2019
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 6 | Impact Score: 5.5 | Exploitability Score: 0.5
VMScore: 393
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An improper certificate validation issue exists in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nxp vybrid_mvf30nn151cku26_firmware -

nxp vybrid_mvf30ns151cku26_firmware -

nxp vybrid_mvf50nn151cmk40_firmware -

nxp vybrid_mvf50nn151cmk50_firmware -

nxp vybrid_mvf50ns151cmk40_firmware -

nxp vybrid_mvf50ns151cmk50_firmware -

nxp vybrid_mvf51nn151cmk50_firmware -

nxp vybrid_mvf51ns151cmk50_firmware -

nxp vybrid_mvf60nn151cmk40_firmware -

nxp vybrid_mvf60ns151cmk40_firmware -

nxp vybrid_mvf60nn151cmk50_firmware -

nxp vybrid_mvf60ns151cmk50_firmware -

nxp vybrid_mvf61nn151cmk50_firmware -

nxp vybrid_mvf61ns151cmk50_firmware -

nxp vybrid_mvf62nn151cmk40_firmware -

nxp i.mx_50_firmware -

nxp i.mx_53_firmware -

nxp i.mx_6ull_firmware -

nxp i.mx_6ultralite_firmware -

nxp i.mx_6sololite_firmware -

nxp i.mx_6solo_firmware -

nxp i.mx_6duallite_firmware -

nxp i.mx_6solox_firmware -

nxp i.mx_6dual_firmware -

nxp i.mx_6quad_firmware -

nxp i.mx_6quadplus_firmware -

nxp i.mx_6dualplus_firmware -

nxp i.mx_28_firmware -

nxp i.mx_7dual_firmware -

nxp i.mx_7solo_firmware -