Impact
A flaw in the openRISC OR1200 core, identified in commit 83ac6b, causes a mismatch between the Register‑Transfer Level (RTL) design and its synthesized netlist. This inconsistency can produce unexpected logic behavior during operation, potentially leading to erroneous output, system crashes, or unpredictable state transitions. The vulnerability stems from a design oversight that results in hardware that does not faithfully implement the intended functional specification.
Affected Systems
The issue affects devices implementing the openRISC OR1200 core that were built using the 83ac6b codebase. This includes board‑level implementations and FPGA designs derived from that commit without subsequent validation against a corrected netlist. No vendor or product list is provided, but any system using the affected core version is potentially vulnerable.
Risk and Exploitability
The EPSS score is not available, and the vulnerability has not been identified in the CISA KEV catalog, indicating limited or no public exploitation data. Given the hardware nature of the flaw, exploitation would likely require physical interaction or firmware manipulation on the affected device, making remote exploitation difficult. Nonetheless, the potential for instability or erratic behavior makes the risk significant for safety‑critical or operational environments where the core is deployed.
OpenCVE Enrichment