CWE-1274

Improper Access Control for Volatile Memory Containing Boot Code

Medium

Description

The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.

Potential Impact

How to Fix

Architecture and Design

Ensure that the design of volatile-memory protections is enough to prevent modification from an adversary or untrusted code.

Testing

Test the volatile-memory protections to ensure they are safe from modification or untrusted code.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1274 vulnerabilities in your codebase.

Get Security Assessment