CWE-1247 - Improper Protection Against Voltage and Clock Glitches
CWE-1247
- Abstraction:
- Base
- Structure:
- Simple
- Status:
- Stable
- Weakness Name
Improper Protection Against Voltage and Clock Glitches
- Description
The device does not contain or contains incorrectly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information or software contained on the device.
A device might support features such as secure boot which are supplemented with hardware and firmware support. This involves establishing a chain of trust, starting with an immutable root of trust by checking the signature of the next stage (culminating with the OS and runtime software) against a golden value before transferring control. The intermediate stages typically set up the system in a secure state by configuring several access control settings. Similarly, security logic for exercising a debug or testing interface may be implemented in hardware, firmware, or both. A device needs to guard against fault attacks such as voltage glitches and clock glitches that an attacker may employ in an attempt to compromise the system.
- Common Consequences
Scope: Confidentiality, Integrity, Availability, Access Control
Impact: Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Memory, Modify Memory, Execute Unauthorized Code or Commands
- Related Weaknesses
- Release Date:
- 2020-02-24
- Latest Modification Date:
- 2023-10-26
Free security scan for your website