Vulnerability Description
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nxp | Vybrid Mvf30Nn151Cku26 Firmware | - |
| Nxp | Vybrid Mvf30Nn151Cku26 | - |
| Nxp | Vybrid Mvf30Ns151Cku26 Firmware | - |
| Nxp | Vybrid Mvf30Ns151Cku26 | - |
| Nxp | Vybrid Mvf50Nn151Cmk40 Firmware | - |
| Nxp | Vybrid Mvf50Nn151Cmk40 | - |
| Nxp | Vybrid Mvf50Nn151Cmk50 Firmware | - |
| Nxp | Vybrid Mvf50Nn151Cmk50 | - |
| Nxp | Vybrid Mvf50Ns151Cmk40 Firmware | - |
| Nxp | Vybrid Mvf50Ns151Cmk40 | - |
| Nxp | Vybrid Mvf50Ns151Cmk50 Firmware | - |
| Nxp | Vybrid Mvf50Ns151Cmk50 | - |
| Nxp | Vybrid Mvf51Nn151Cmk50 Firmware | - |
| Nxp | Vybrid Mvf51Nn151Cmk50 | - |
| Nxp | Vybrid Mvf51Ns151Cmk50 Firmware | - |
| Nxp | Vybrid Mvf51Ns151Cmk50 | - |
| Nxp | Vybrid Mvf60Nn151Cmk40 Firmware | - |
| Nxp | Vybrid Mvf60Nn151Cmk40 | - |
| Nxp | Vybrid Mvf60Ns151Cmk40 Firmware | - |
| Nxp | Vybrid Mvf60Ns151Cmk40 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99966Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-152-02Third Party AdvisoryUS Government ResourceVDB Entry
- http://www.securityfocus.com/bid/99966Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-152-02Third Party AdvisoryUS Government ResourceVDB Entry
FAQ
What is CVE-2017-7932?
CVE-2017-7932 is a vulnerability with a CVSS score of 6.0 (MEDIUM). An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.M...
How severe is CVE-2017-7932?
CVE-2017-7932 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7932?
Check the references section above for vendor advisories and patch information. Affected products include: Nxp Vybrid Mvf30Nn151Cku26 Firmware, Nxp Vybrid Mvf30Nn151Cku26, Nxp Vybrid Mvf30Ns151Cku26 Firmware, Nxp Vybrid Mvf30Ns151Cku26, Nxp Vybrid Mvf50Nn151Cmk40 Firmware.