Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DENX Software Engineering U-Boot 输入验证错误漏洞
Vulnerability Description
DENX Software Engineering U-Boot是德国DENX Software Engineering公司的一套可以从AES加密文件读取设备配置的引导加载程序。 DENX Software Engineering U-Boot中的Verified boot签名验证存在输入验证漏洞。攻击者可借助特制的FIT图像及设备内存功能利用该漏洞绕过签名检测。
CVSS Information
N/A
Vulnerability Type
N/A