Power, Clock, and Reset Concerns
A category in the Common Weakness Enumeration published by The MITRE Corporation.
Summary
Categories in the Common Weakness Enumeration (CWE) group entries based on some common characteristic or attribute.
Weaknesses in this category are related to system power, voltage, current, temperature, clocks, system state saving/restoring, and resets at the platform and SoC level.
Weaknesses
A device's real time power consumption may be monitored during security token evaluation and the information gleaned may be used to determine the value of the referenc...
Software-controllable device functionality such as power and clock management permits unauthorized modification of memory or register bits.
Register lock bit protection disables changes to system configuration once the bit is set. Some of the protected registers or lock bits become programmable after power...
Untrusted agents can disable alerts about signal conditions exceeding limits or the response mechanism that handles such alerts.
A hardware device is missing or has inadequate protection features to prevent overheating.
The product performs a power save/restore operation, but it does not ensure that the integrity of the configuration state is maintained and/or ...
The device is missing or incorrectly implements circuitry or sensors to detect and mitigate CPU instruction skips that can be caused by...
The device does not contain or contains improperly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information...
The device does not write-protect the parametric data values for sensors that scale the sensor value, allowing untrusted software to manipulate the apparent result and...
Security-critical logic is not set to a known value on reset.
Concepts
This view organizes weaknesses around concepts that are frequently used or encountered in hardware design. Accordingly, this view can align closely with the perspectiv...
Common Weakness Enumeration content on this website is copyright of The MITRE Corporation unless otherwise specified. Use of the Common Weakness Enumeration and the associated references on this website are subject to the Terms of Use as specified by The MITRE Corporation.