CVE-2022-23822

CVE-2022-23822

Vendor Amd-Xilinx
Product Zynq-7000 SoC FSBL
Weakness CWE-863 · Incorrect authorization
Published April 27, 2022
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.

Key dates

02Disclosure timeline

April 27, 2022 CVE published
September 16, 2024 Record updated