Umbra Wiki weakness weakness/CWE-1189
Back to wiki

CWE-1189 — Improper Isolation of Shared Resources on System-on-a-Chip (SoC)

provenance: imported · CWE: CWE-1189

CWE-1189: Improper Isolation of Shared Resources on System-on-a-Chip (SoC)

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Stable
Likelihood of exploit

Description

The System-On-a-Chip (SoC) does not properly isolate shared resources between trusted and untrusted agents.

A System-On-a-Chip (SoC) has a lot of functionality, but it may have a limited number of pins or pads. A pin can only perform one function at a time. However, it can be configured to perform multiple different functions. This technique is called pin multiplexing. Similarly, several resources on the chip may be shared to multiplex and support different features or functions. When such resources are shared between trusted and untrusted agents, untrusted agents may be able to access the assets intended to be accessed only by the trusted agents.

Common consequences

  • Access Control: Bypass Protection Mechanism
  • Integrity: Quality Degradation

Mitigations

Architecture and Design — When sharing resources, avoid mixing agents of varying trust levels. Untrusted agents should not share resources with trusted agents.

References

  • CWE page: https://cwe.mitre.org/data/definitions/1189.html
  • CWE list: https://cwe.mitre.org/data/index.html