Impact
An issue was identified in the openRISC OR1200 processor at commit 83ac6b where an incorrect update of the program counter values occurs when special purpose registers change. This flaw, identified as CWE-691, does not enable code execution or data disclosure; instead it can cause the processor to halt or become unresponsive, resulting in a loss of availability for any system relying on the affected hardware or emulation. The likely attack vector is a privileged local modification of special purpose registers, as no remote exploitation pathway is documented.
Affected Systems
The vulnerability is confined to the openRISC OR1200 architecture. Any deployments or emulators that incorporate the code up to commit 83ac6b and have not been updated beyond that commit are potentially affected. No vendor or product name is attached, so the impact spans all instances using the vulnerable code path.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw requires the trigger of an SPR change, which is typically a privileged or local operation; no remote exploitation pathway is documented. Because the vulnerability is not listed in the CISA KEV catalog and no active exploits are known, the overall risk remains moderate, primarily driven by the possibility of a locally privileged attacker inducing a denial of service.
OpenCVE Enrichment