ID

VAR-201708-1391


CVE

CVE-2017-7932


TITLE

plural NXP i.MX and Vybrid Certificate validation vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2017-007267

DESCRIPTION

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image. plural NXP i.MX and Vybrid The product contains a certificate validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NXPi.MX50 and so on are different series of microprocessor products from NXPSemiconductors of the Netherlands. There are security vulnerabilities in several NXPi.MX products due to the program failing to properly validate the certificate. Failed exploit attempts will likely cause a denial-of-service condition. The following devices are affected: NXP i.MX 28, i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i. MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus

Trust: 2.7

sources: NVD: CVE-2017-7932 // JVNDB: JVNDB-2017-007267 // CNVD: CNVD-2017-23000 // BID: 99966 // IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b // VULHUB: VHN-116135

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b // CNVD: CNVD-2017-23000

AFFECTED PRODUCTS

vendor:nxpmodel:i.mx 50scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 53scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6ultralitescope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf62nn151cmk40scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6soloscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf61ns151cmk50scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf61nn151cmk50scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6ullscope:eqversion: -

Trust: 1.6

vendor:nxpmodel:i.mx 6sololitescope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf60nn151cmk40scope:eqversion: -

Trust: 1.6

vendor:nxpmodel:vybrid mvf30nn151cku26scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50nn151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 7dualscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 7soloscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60ns151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6soloxscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6dualscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf30ns151cku26scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf60nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 28scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf51ns151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6dualplusscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf50ns151cmk40scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6duallitescope:eqversion: -

Trust: 1.0

vendor:nxpmodel:vybrid mvf51nn151cmk50scope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6quadscope:eqversion: -

Trust: 1.0

vendor:nxpmodel:i.mx 6quadplusscope:eqversion: -

Trust: 1.0

vendor:nxp semiconductorsmodel:i.mx 28scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 53scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6dualscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6duallitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6dualplusscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6quadscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6quadplusscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6soloscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6sololitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6soloxscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6ullscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 6ultralitescope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 7dualscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:i.mx 7soloscope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf30nn151cku26scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf30ns151cku26scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50ns151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf50ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf51nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf51ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60ns151cmk40scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf60ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf61nn151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf61ns151cmk50scope: - version: -

Trust: 0.8

vendor:nxp semiconductorsmodel:vybrid mvf62nn151cmk40scope: - version: -

Trust: 0.8

vendor:nxpmodel:semiconductors i.mxscope:eqversion:50

Trust: 0.6

vendor:nxpmodel:semiconductors i.mxscope:eqversion:53

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6ullscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6ultralitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6sololitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6soloscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6duallitescope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6quadscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6soloxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6dualscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6dualplusscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 6quadplusscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf3xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf5xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf6xxscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mxscope:eqversion:28

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 7soloscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors i.mx 7dualscope: - version: -

Trust: 0.6

vendor:nxpmodel:semiconductors vybrid vf5xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors vybrid vf3xxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare ultralightscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare reader componentsscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors mifare desfire ev1scope: - version: -

Trust: 0.3

vendor:nxpmodel:semiconductors mifare classicscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 7dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ultralitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6ullscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloxscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6sololitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6soloscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6quadscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualplusscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6duallitescope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imx 6dualscope:eqversion:0

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:530

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:500

Trust: 0.3

vendor:nxpmodel:semiconductors imxscope:eqversion:280

Trust: 0.3

vendor:vybrid mvf30nn151cku26model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60ns151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf61nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf61ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf62nn151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 50model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 53model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6ullmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6ultralitemodel: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf30ns151cku26model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6sololitemodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6solomodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6duallitemodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6soloxmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6dualmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6quadmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6quadplusmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 6dualplusmodel: - scope:eqversion: -

Trust: 0.2

vendor:i mx 28model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 7dualmodel: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50nn151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:i mx 7solomodel: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50ns151cmk40model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf50ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf51nn151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf51ns151cmk50model: - scope:eqversion: -

Trust: 0.2

vendor:vybrid mvf60nn151cmk40model: - scope:eqversion: -

Trust: 0.2

sources: IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b // CNVD: CNVD-2017-23000 // BID: 99966 // JVNDB: JVNDB-2017-007267 // CNNVD: CNNVD-201704-928 // NVD: CVE-2017-7932

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7932
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-7932
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-23000
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-928
value: MEDIUM

Trust: 0.6

IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b
value: MEDIUM

Trust: 0.2

VULHUB: VHN-116135
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-7932
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-23000
severity: MEDIUM
baseScore: 5.9
vectorString: AV:L/AC:H/AU:N/C:P/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.9
impactScore: 9.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b
severity: MEDIUM
baseScore: 5.9
vectorString: AV:L/AC:H/AU:N/C:P/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.9
impactScore: 9.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-116135
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7932
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.5
impactScore: 5.5
version: 3.0

Trust: 1.8

sources: IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b // CNVD: CNVD-2017-23000 // VULHUB: VHN-116135 // JVNDB: JVNDB-2017-007267 // CNNVD: CNNVD-201704-928 // NVD: CVE-2017-7932

PROBLEMTYPE DATA

problemtype:CWE-295

Trust: 1.9

sources: VULHUB: VHN-116135 // JVNDB: JVNDB-2017-007267 // NVD: CVE-2017-7932

THREAT TYPE

local

Trust: 0.9

sources: BID: 99966 // CNNVD: CNNVD-201704-928

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201704-928

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-007267

PATCH

title:i.MX & Vybrid Security Vulnerability Errata - ERR010872, ERR010873url:https://community.nxp.com/docs/DOC-334996

Trust: 0.8

title:Multiple NXPi.MX products verify patches that bypass the vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/100888

Trust: 0.6

title:Multiple NXP i.MX Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=99743

Trust: 0.6

sources: CNVD: CNVD-2017-23000 // JVNDB: JVNDB-2017-007267 // CNNVD: CNNVD-201704-928

EXTERNAL IDS

db:NVDid:CVE-2017-7932

Trust: 3.6

db:ICS CERTid:ICSA-17-152-02

Trust: 3.4

db:BIDid:99966

Trust: 2.6

db:CNNVDid:CNNVD-201704-928

Trust: 0.9

db:CNVDid:CNVD-2017-23000

Trust: 0.8

db:JVNDBid:JVNDB-2017-007267

Trust: 0.8

db:IVDid:D823AA2F-DC34-445F-8238-CACBE1C66F3B

Trust: 0.2

db:VULHUBid:VHN-116135

Trust: 0.1

sources: IVD: d823aa2f-dc34-445f-8238-cacbe1c66f3b // CNVD: CNVD-2017-23000 // VULHUB: VHN-116135 // BID: 99966 // JVNDB: JVNDB-2017-007267 // CNNVD: CNNVD-201704-928 // NVD: CVE-2017-7932

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-152-02

Trust: 3.4

url:http://www.securityfocus.com/bid/99966

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7932

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7932

Trust: 0.8

url:http://www.nxp.com/

Trust: 0.3

sources: CNVD: CNVD-2017-23000 // VULHUB: VHN-116135 // BID: 99966 // JVNDB: JVNDB-2017-007267 // CNNVD: CNNVD-201704-928 // NVD: CVE-2017-7932

CREDITS

Quarkslab.

Trust: 0.3

sources: BID: 99966

SOURCES

db:IVDid:d823aa2f-dc34-445f-8238-cacbe1c66f3b
db:CNVDid:CNVD-2017-23000
db:VULHUBid:VHN-116135
db:BIDid:99966
db:JVNDBid:JVNDB-2017-007267
db:CNNVDid:CNNVD-201704-928
db:NVDid:CVE-2017-7932

LAST UPDATE DATE

2025-04-20T23:29:34.888000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-23000date:2017-08-26T00:00:00
db:VULHUBid:VHN-116135date:2019-10-09T00:00:00
db:BIDid:99966date:2017-07-26T00:00:00
db:JVNDBid:JVNDB-2017-007267date:2017-09-14T00:00:00
db:CNNVDid:CNNVD-201704-928date:2019-10-17T00:00:00
db:NVDid:CVE-2017-7932date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:d823aa2f-dc34-445f-8238-cacbe1c66f3bdate:2017-08-26T00:00:00
db:CNVDid:CNVD-2017-23000date:2017-08-26T00:00:00
db:VULHUBid:VHN-116135date:2017-08-07T00:00:00
db:BIDid:99966date:2017-07-26T00:00:00
db:JVNDBid:JVNDB-2017-007267date:2017-09-14T00:00:00
db:CNNVDid:CNNVD-201704-928date:2017-04-20T00:00:00
db:NVDid:CVE-2017-7932date:2017-08-07T08:29:00.307