CWE-1290

Incorrect Decoding of Security Identifiers

Medium

Description

The product implements a decoding mechanism to decode certain bus-transaction signals to security identifiers. If the decoding is implemented incorrectly, then untrusted agents can now gain unauthorized access to the asset.

Potential Impact

How to Fix

Architecture and Design

Security identifier decoders must be reviewed for design consistency and common weaknesses.

Implementation

Access and programming flows must be tested in pre-silicon and post-silicon testing in order to check for this weakness.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1290 vulnerabilities in your codebase.

Get Security Assessment