Impact
Insufficient verification in Caliptra Core ROM and Core Firmware's validate_debug_unlock_token() allows a token issued for one device to unlock production debug on another device that shares the same unlock authority key hash. The 384‑bit challenge nonce still blocks replay attacks, but the vulnerability removes the per-device binding that should restrict debug unlock to the intended device.
Affected Systems
Affected vendor Caliptra includes the Core ROM and Core Firmware products. Core ROM versions 2.0.0 through 2.0.2 and 2.1.0 through 2.1.1 are impacted, as are Core Firmware versions 2.0.0 through 2.0.1 and 2.1.0.
Risk and Exploitability
The CVSS score of 1.8 indicates a low severity vulnerability, and the EPSS score is not available while it is not in the CISA KEV catalog. The likely attack vector requires an attacker to have access to the integrator's debug unlock signing service, enabling the issuance of a valid token for a target device. This bypass only affects devices that share the same unlock authority key and does not extend to devices outside that set, so the overall risk to broader systems remains limited.
OpenCVE Enrichment