Vulnerability Description
The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register not being defined, potentially leading to information disclosure, data tampering and denial of service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Risc-V | Instruction Set Manual | All versions |
Related Weaknesses (CWE)
References
- https://riscv.org/news/2021/08/video-glitching-risc-v-chips-mtvec-corruption-forExploitVendor Advisory
- https://riscv.org/news/2021/08/video-glitching-risc-v-chips-mtvec-corruption-forExploitVendor Advisory
FAQ
What is CVE-2021-1104?
CVE-2021-1104 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register no...
How severe is CVE-2021-1104?
CVE-2021-1104 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-1104?
Check the references section above for vendor advisories and patch information. Affected products include: Risc-V Instruction Set Manual.