CWE-1231 – Improper Prevention of Lock Bit Modification

Read Time:29 Second

Description

The product uses a trusted lock bit for restricting access to registers, address regions, or other resources, but the product does not prevent the value of the lock bit from being modified after it has been set.

Modes of Introduction:

– Architecture and Design

 

 

Related Weaknesses

CWE-284

 

Consequences

Access Control: Modify Memory

Registers protected by lock bit can be modified even when lock is set.

 

Potential Mitigations

Phase: Architecture and Design, Implementation, Testing

Effectiveness: High

Description: 

CVE References

  • CVE-2017-6283
    • chip reset clears critical read/write lock permissions for RSA function