An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.

Project Subscriptions

Vendors Products
I.mx 28 Subscribe
I.mx 28 Firmware Subscribe
I.mx 50 Subscribe
I.mx 50 Firmware Subscribe
I.mx 53 Subscribe
I.mx 53 Firmware Subscribe
I.mx 6dual Subscribe
I.mx 6dual Firmware Subscribe
I.mx 6duallite Subscribe
I.mx 6duallite Firmware Subscribe
I.mx 6dualplus Subscribe
I.mx 6dualplus Firmware Subscribe
I.mx 6quad Subscribe
I.mx 6quad Firmware Subscribe
I.mx 6quadplus Subscribe
I.mx 6quadplus Firmware Subscribe
I.mx 6solo Subscribe
I.mx 6solo Firmware Subscribe
I.mx 6sololite Subscribe
I.mx 6sololite Firmware Subscribe
I.mx 6solox Subscribe
I.mx 6solox Firmware Subscribe
I.mx 6ull Subscribe
I.mx 6ull Firmware Subscribe
I.mx 6ultralite Subscribe
I.mx 6ultralite Firmware Subscribe
I.mx 7dual Subscribe
I.mx 7dual Firmware Subscribe
I.mx 7solo Subscribe
I.mx 7solo Firmware Subscribe
Vybrid Mvf30nn151cku26 Subscribe
Vybrid Mvf30nn151cku26 Firmware Subscribe
Vybrid Mvf30ns151cku26 Subscribe
Vybrid Mvf30ns151cku26 Firmware Subscribe
Vybrid Mvf50nn151cmk40 Subscribe
Vybrid Mvf50nn151cmk40 Firmware Subscribe
Vybrid Mvf50nn151cmk50 Subscribe
Vybrid Mvf50nn151cmk50 Firmware Subscribe
Vybrid Mvf50ns151cmk40 Subscribe
Vybrid Mvf50ns151cmk40 Firmware Subscribe
Vybrid Mvf50ns151cmk50 Subscribe
Vybrid Mvf50ns151cmk50 Firmware Subscribe
Vybrid Mvf51nn151cmk50 Subscribe
Vybrid Mvf51nn151cmk50 Firmware Subscribe
Vybrid Mvf51ns151cmk50 Subscribe
Vybrid Mvf51ns151cmk50 Firmware Subscribe
Vybrid Mvf60nn151cmk40 Subscribe
Vybrid Mvf60nn151cmk40 Firmware Subscribe
Vybrid Mvf60nn151cmk50 Subscribe
Vybrid Mvf60nn151cmk50 Firmware Subscribe
Vybrid Mvf60ns151cmk40 Subscribe
Vybrid Mvf60ns151cmk40 Firmware Subscribe
Vybrid Mvf60ns151cmk50 Subscribe
Vybrid Mvf60ns151cmk50 Firmware Subscribe
Vybrid Mvf61nn151cmk50 Subscribe
Vybrid Mvf61nn151cmk50 Firmware Subscribe
Vybrid Mvf61ns151cmk50 Subscribe
Vybrid Mvf61ns151cmk50 Firmware Subscribe
Vybrid Mvf62nn151cmk40 Subscribe
Vybrid Mvf62nn151cmk40 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-16903 An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T16:19:29.197Z

Reserved: 2017-04-18T00:00:00

Link: CVE-2017-7932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-08-07T08:29:00.307

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-7932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses