CVE Database
/

CVE-2017-3225

Back to search

CVE-2017-3225

Published: Jul 24, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this environment encryption mode, U-Boot's use of a zero initialization vector may allow attacks against the underlying cryptographic implementation and allow an attacker to decrypt the data. Das U-Boot's AES-CBC encryption feature uses a zero (0) initialization vector. This allows an attacker to perform dictionary attacks on encrypted data produced by Das U-Boot to learn information about the encrypted data.

VendorProductVersions

Das

U-Boot

affected
2017.09 - < 2017.09

Weaknesses (CWE)

References

100675
vdb-entry
x_refsource_BID
VU#166743
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now