Impact
A missing authorization check (CWE-862) in Caliptra Core Runtime Firmware allows unverified AXI addresses in subsystem mode, resulting in a denial of service. The flaw does not reveal additional confidentiality or integrity impacts beyond the availability loss, and any further consequences are integration‑specific.
Affected Systems
The vulnerability affects Caliptra Core Runtime Firmware version 2.1.0.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score is <1%. The flaw is not listed in CISA KEV. It can be exploited by a privileged local user who can issue mailbox commands, providing a direct path to service disruption.
OpenCVE Enrichment