CWE-1239

Improper Zeroization of Hardware Register

Medium

Description

The hardware product does not properly clear sensitive information from built-in registers when the user of the hardware block changes.

Potential Impact

How to Fix

Architecture and Design

Every register potentially containing sensitive information must have a policy specifying how and when information is cleared, in addition to clarifying if it is the responsibility of the hardware logic or IP user to initiate the zeroization procedure at the appropriate time.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1239 vulnerabilities in your codebase.

Get Security Assessment