CVE-2019-5478

A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amd:zu11eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu11eg:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amd:zu15eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu15eg:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amd:zu17eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu17eg:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amd:zu19eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu19eg:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amd:zu1cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu1cg:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amd:zu1eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu1eg:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amd:zu21dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu21dr:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amd:zu25dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu25dr:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amd:zu27dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu27dr:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amd:zu28dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu28dr:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amd:zu29dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu29dr:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amd:zu2cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu2cg:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amd:zu2eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu2eg:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amd:zu39dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu39dr:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:amd:zu3cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu3cg:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:amd:zu3eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu3eg:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:amd:zu3tcg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu3tcg:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:amd:zu3teg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu3teg:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:amd:zu42dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu42dr:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:amd:zu43dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu43dr:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:amd:zu46dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu46dr:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:amd:zu47dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu47dr:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:amd:zu48dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu48dr:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:amd:zu49dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu49dr:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:amd:zu4cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu4cg:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:amd:zu4eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu4eg:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:amd:zu4ev_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu4ev:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:amd:zu5cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu5cg:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:amd:zu5eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu5eg:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:amd:zu5ev_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu5ev:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:amd:zu63dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu63dr:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:amd:zu64dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu64dr:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:amd:zu65dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu65dr:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:amd:zu67dr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu67dr:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:amd:zu6cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu6cg:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:amd:zu6eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu6eg:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:amd:zu7cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu7cg:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:amd:zu7eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu7eg:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:amd:zu7ev_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu7ev:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:amd:zu9cg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu9cg:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:amd:zu9eg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:zu9eg:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-03 20:15

Updated : 2024-11-27 16:10


NVD link : CVE-2019-5478

Mitre link : CVE-2019-5478

CVE.ORG link : CVE-2019-5478


JSON object : View

Products Affected

amd

  • zu43dr_firmware
  • zu9cg
  • zu9eg
  • zu47dr
  • zu7ev
  • zu15eg
  • zu47dr_firmware
  • zu9eg_firmware
  • zu19eg
  • zu19eg_firmware
  • zu6cg_firmware
  • zu17eg_firmware
  • zu5ev
  • zu29dr
  • zu28dr
  • zu67dr_firmware
  • zu7eg
  • zu4cg
  • zu5cg
  • zu4eg
  • zu39dr
  • zu2cg_firmware
  • zu3tcg_firmware
  • zu27dr
  • zu11eg
  • zu4ev
  • zu29dr_firmware
  • zu3tcg
  • zu6eg_firmware
  • zu3teg
  • zu7cg_firmware
  • zu5eg
  • zu28dr_firmware
  • zu11eg_firmware
  • zu46dr
  • zu46dr_firmware
  • zu1cg_firmware
  • zu49dr_firmware
  • zu48dr
  • zu25dr_firmware
  • zu7ev_firmware
  • zu2cg
  • zu15eg_firmware
  • zu63dr_firmware
  • zu6cg
  • zu3cg_firmware
  • zu64dr
  • zu3eg
  • zu9cg_firmware
  • zu5ev_firmware
  • zu1cg
  • zu43dr
  • zu7cg
  • zu2eg
  • zu67dr
  • zu7eg_firmware
  • zu21dr_firmware
  • zu42dr
  • zu65dr
  • zu64dr_firmware
  • zu1eg_firmware
  • zu6eg
  • zu39dr_firmware
  • zu5cg_firmware
  • zu17eg
  • zu21dr
  • zu42dr_firmware
  • zu4ev_firmware
  • zu25dr
  • zu5eg_firmware
  • zu65dr_firmware
  • zu3eg_firmware
  • zu49dr
  • zu3teg_firmware
  • zu63dr
  • zu3cg
  • zu4cg_firmware
  • zu2eg_firmware
  • zu1eg
  • zu4eg_firmware
  • zu27dr_firmware
  • zu48dr_firmware
CWE
CWE-657

Violation of Secure Design Principles

CWE-345

Insufficient Verification of Data Authenticity