Impact
A mismatch between the PCPI instruction field and the corresponding memory address in the PicoRV32 core can cause unintended memory operations, resulting in buffer overflows or type confusion. The vulnerability does not explicitly mention code execution, so the primary consequence is memory corruption that could compromise data integrity or system stability if exploited.
Affected Systems
All designs that incorporate the open‑source PicoRV32 core with commit 87c89a or earlier are impacted. The core is widely used in FPGA and ASIC projects, and any vendor‑specific implementation that compiles this code without patch is also at risk. No official CNA product list is available, so any system using this code must verify its build source.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑high severity, while the EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability does not specify an attack vector, but the memory corruption risk implies that an attacker would need to trigger the PCPI mismatch through the hardware interface, likely requiring physical access or device-level compromise. The CVE is not listed in CISA’s KEV catalog, further indicating limited known exploitation. Overall, the risk is moderate but the potential impact warrants timely remediation.
OpenCVE Enrichment