Impact
An inconsistency between the Register‑Transfer Level description and the synthesized netlist of the openRISC OR1200 core was identified in commit 83ac6b. The mismatch can cause the hardware to execute logic paths that were not intended by the design, potentially generating incorrect outputs, producing erratic state changes, or triggering system crashes. The vulnerability results from a design oversight that prevents the RTL and netlist from faithfully representing the same functionality, leading to unpredictable hardware behavior.
Affected Systems
The issue applies to any device that implements the openRISC OR1200 core built from the 83ac6b codebase. No vendor, product, or version list is provided, so all hardware or FPGA designs derived from that commit without a subsequent verification against a corrected netlist are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity risk, while the EPSS score of <1% suggests a very low probability that attackers are actively exploiting the flaw at this time. The vulnerability has not been listed in the CISA KEV catalog, implying no known exploitation in the wild. Based on the description, it is inferred that exploitation would likely require physical interaction with the device or manipulation of its firmware/FPGA configuration, making remote exploitation difficult. Nonetheless, the potential for destabilizing or erratic behavior poses a significant risk to safety‑critical or operational environments where the core is deployed.
OpenCVE Enrichment