CWE-1326 类弱点 8 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-1326指硬件中缺失不可变的信任根,导致安全启动机制失效。攻击者可利用此缺陷绕过固件验证,执行恶意或未经授权的引导代码,从而完全控制设备底层。开发者需确保SoC内置硬件级只读密钥或熔丝,严格验证签名链,防止信任根被篡改或替换,从物理层面确立可信启动基础,阻断恶意代码注入路径。
... always_ff @(posedge clk_i) begin if (req_i) begin if (!we_i) begin raddr_q <= addr_i[$clog2(RomSize)-1+3:3]; end else begin mem[addr_i[$clog2(RomSize)-1+3:3]] <= wdata_i; end end end ... // this prevents spurious Xes from propagating into the speculative fetch stage of the core assign rdata_o = (raddr_q < RomSize) ? mem[raddr_q] : '0; ...... always_ff @(posedge clk_i) begin if (req_i) begin raddr_q <= addr_i[$clog2(RomSize)-1+3:3]; end end ... // this prevents spurious Xes from propagating into the speculative fetch stage of the core assign rdata_o = (raddr_q < RomSize) ? mem[raddr_q] : '0; ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-34502 | Light & Wonder Deck Mate 安全漏洞 — Deck Mate 2 | 6.8 | - | 2025-10-24 |
| CVE-2025-5834 | Pioneer DMH-WT7600NEX 安全漏洞 — DMH-WT7600NEX | 7.8AI | HighAI | 2025-06-25 |
| CVE-2025-31929 | Siemens VersiCharge AC Series 安全漏洞 — IEC 1Ph 7.4kW Child socket | 4.2 | Medium | 2025-05-13 |
| CVE-2025-2762 | CarlinKit CPC200-CCPA 安全漏洞 — CPC200-CCPA | 7.8 | - | 2025-04-23 |
| CVE-2024-8357 | Visteon Infotainment 安全漏洞 — Infotainment | 7.8 | - | 2024-11-22 |
| CVE-2024-30111 | HCL Technologies HCL DRYiCE AEX 安全漏洞 — DRYiCE AEX | 3.3 | Low | 2024-06-28 |
| CVE-2024-32742 | Siemens SIMATIC CN 4100 安全漏洞 — SIMATIC CN 4100 | 7.6 | High | 2024-05-14 |
| CVE-2022-38773 | Siemens SIMATIC S7-1500 安全漏洞 — SIMATIC Drive Controller CPU 1504D TF | 4.6 | Medium | 2023-01-10 |
CWE-1326 是常见的弱点类别,本平台收录该类弱点关联的 8 条 CVE 漏洞。