CWE-1283

Mutable Attestation or Measurement Reporting Data

Medium

Description

The register contents used for attestation or measurement reporting data to verify boot flow are modifiable by an adversary.

Potential Impact

How to Fix

Architecture and Design

Measurement data should be stored in registers that are read-only or otherwise have access controls that prevent modification by an untrusted agent.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1283 vulnerabilities in your codebase.

Get Security Assessment