BaseIncomplete

CWE-1315Improper Setting of Bus Controlling Capability in Fabric End-point

Category: other

Description

The bus controller enables bits in the fabric end-point to allow responder devices to control transactions on the fabric.

Common consequences· 1

  • Access Control — Modify Memory, Read Memory, Bypass Protection Mechanism

Potential mitigations· 3

  • [Architecture and Design]For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-controlling capability.
  • [Implementation]For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-controlling capability.
  • [System Configuration]For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-controlling capability.

Related CAPEC attack patterns· 2

CAPEC-1CAPEC-180

References

  1. https://cwe.mitre.org/data/definitions/1315.html

Exploits (incoming)2

TypeTargetConfidenceTier
AttackPatternAccessing Functionality Not Properly Constrained by ACLscapec-1100%live
AttackPatternExploiting Incorrectly Configured Access Control Security Levelscapec-180100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Improper Translation of Security Attributes by Fabric Bridge
CWE
Power-On of Untrusted Execution Core Before Enabling Fabric Access Control
CWE
Improper Access Control in Fabric Bridge
CWE
Missing Support for Security Features in On-chip Fabrics or Buses
CWE
Policy Privileges are not Assigned Consistently Between Control and Data Agents
CWE
Improper Protection for Outbound Error Messages and Alert Signals
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.