CWE-1271 — Uninitialized Value on Reset for Registers Holding Security Settings
CWE-1271: Uninitialized Value on Reset for Registers Holding Security Settings
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
Security-critical logic is not set to a known value on reset.
When the device is first brought out of reset, the state of registers will be indeterminate if they have not been initialized by the logic. Before the registers are initialized, there will be a window during which the device is in an insecure state and may be vulnerable to attack.
Common consequences
- Access Control, Authentication, Authorization: Varies by Context
Mitigations
Implementation — Design checks should be performed to identify any uninitialized flip-flops used for security-critical functions.
Architecture and Design — All registers holding security-critical information should be set to a specific value on reset.
References
- CWE page: https://cwe.mitre.org/data/definitions/1271.html
- CWE list: https://cwe.mitre.org/data/index.html