Vulnerability Details CVE-2021-27208
When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could lead to arbitrary code execution. Physical access and modification of the board assembly on which the Zynq-7000 SoC device mounted is needed to replace the original NAND flash memory with a NAND flash emulation device for this attack to be successful.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.4%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.6
Products affected by CVE-2021-27208
-
cpe:2.3:h:xilinx:zynq-7000:-
-
cpe:2.3:h:xilinx:zynq-7000s:-
-
cpe:2.3:o:xilinx:zynq-7000_firmware:-
-
cpe:2.3:o:xilinx:zynq-7000s_firmware:-