Impact
Caliptra Core ROM contains a time‑of‑check/time‑of‑use flaw in the UpdateResetFlow routine. The error occurs because AXI staging addresses supplied by the caller are not validated against the strap‑configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR. As a result, after a firmware image has been verified, a compromised loader can change the image in SRAM prior to its transfer into the instruction cache (ICCM) while the attestation module continues to report the original image digest. This allows silent firmware tampering that bypasses secure boot. The weakness is a classic input‑validation error (CWE‑20) combined with a TOCTOU race condition (CWE‑367).
Affected Systems
Affected product is Caliptra Core ROM, versions 2.1.0 through 2.1.1, used in subsystem mode. Systems that embed these core ROM images in hardware clones or custom SoCs will be impacted unless they adopt a later firmware version.
Risk and Exploitability
The CVSS score of 5.6 places the vulnerability in the moderate severity range. The EPSS score of less than 1 % indicates that automated exploitation is unlikely at present. Because the flaw requires a compromised local firmware that can control the AXI bus to SRAM, the attack surface is limited to insider or supply‑chain threats, not remote attackers. As it is not listed in the CISA KEV catalog, no large‑scale exploitation activity has been reported, but the potential for undetected firmware compromise remains.
OpenCVE Enrichment