PT-2026-67570 · Unknown · Caliptra Core Rom
CVE-2026-11835
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Caliptra Core ROM versions 2.1.0 through 2.1.1
Description
A Time-of-check time-of-use (TOCTOU) issue combined with missing input validation in the
UpdateResetFlow::run() function in subsystem mode allows a local attacker to bypass secure boot. By providing an AXI staging address that is not validated against the SS EXTERNAL STAGING AREA BASE ADDR, an attacker can modify firmware between the verification phase and its loading into the Instruction Cache and Tightly Coupled Memory (ICCM). This allows the compromise to remain hidden as attestation continues to report the digest of the originally verified image. Successful exploitation requires compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Caliptra Core Rom