Umbra Wiki weakness weakness/CWE-1271
Back to wiki

CWE-1271 — Uninitialized Value on Reset for Registers Holding Security Settings

provenance: imported · CWE: CWE-1271

CWE-1271: Uninitialized Value on Reset for Registers Holding Security Settings

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Incomplete
Likelihood of exploit

Description

Security-critical logic is not set to a known value on reset.

When the device is first brought out of reset, the state of registers will be indeterminate if they have not been initialized by the logic. Before the registers are initialized, there will be a window during which the device is in an insecure state and may be vulnerable to attack.

Common consequences

  • Access Control, Authentication, Authorization: Varies by Context

Mitigations

Implementation — Design checks should be performed to identify any uninitialized flip-flops used for security-critical functions.

Architecture and Design — All registers holding security-critical information should be set to a specific value on reset.

References

  • CWE page: https://cwe.mitre.org/data/definitions/1271.html
  • CWE list: https://cwe.mitre.org/data/index.html