CVE-2017-7932

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.

Published: 2017-08-07 Last update: 2026-05-13 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-7932 is rated Low Risk (30.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.26%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2017-7932

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.02% 0.26% +0.23%
2 2025-03-17 0.17% 0.02% -0.15%
3 2024-12-17 0.17%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-7932

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.0 3.0 MEDIUM
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.5 5.5 [email protected]
4.4 2.0 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.4 6.4 [email protected]

Weakness enumeration for CVE-2017-7932

Affected software / configurations for CVE-2017-7932

Vendor Product Version Raw CPE
nxp vybrid_mvf30nn151cku26_firmware cpe:2.3:o:nxp:vybrid_mvf30nn151cku26_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf30ns151cku26_firmware cpe:2.3:o:nxp:vybrid_mvf30ns151cku26_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf50nn151cmk40_firmware cpe:2.3:o:nxp:vybrid_mvf50nn151cmk40_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf50nn151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf50nn151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf50ns151cmk40_firmware cpe:2.3:o:nxp:vybrid_mvf50ns151cmk40_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf50ns151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf50ns151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf51nn151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf51nn151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf51ns151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf51ns151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf60nn151cmk40_firmware cpe:2.3:o:nxp:vybrid_mvf60nn151cmk40_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf60ns151cmk40_firmware cpe:2.3:o:nxp:vybrid_mvf60ns151cmk40_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf60nn151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf60nn151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf60ns151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf60ns151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf61nn151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf61nn151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf61ns151cmk50_firmware cpe:2.3:o:nxp:vybrid_mvf61ns151cmk50_firmware:-:*:*:*:*:*:*:*
nxp vybrid_mvf62nn151cmk40_firmware cpe:2.3:o:nxp:vybrid_mvf62nn151cmk40_firmware:-:*:*:*:*:*:*:*
nxp i.mx_50_firmware cpe:2.3:o:nxp:i.mx_50_firmware:-:*:*:*:*:*:*:*
nxp i.mx_53_firmware cpe:2.3:o:nxp:i.mx_53_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6ull_firmware cpe:2.3:o:nxp:i.mx_6ull_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6ultralite_firmware cpe:2.3:o:nxp:i.mx_6ultralite_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6sololite_firmware cpe:2.3:o:nxp:i.mx_6sololite_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6solo_firmware cpe:2.3:o:nxp:i.mx_6solo_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6duallite_firmware cpe:2.3:o:nxp:i.mx_6duallite_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6solox_firmware cpe:2.3:o:nxp:i.mx_6solox_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6dual_firmware cpe:2.3:o:nxp:i.mx_6dual_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6quad_firmware cpe:2.3:o:nxp:i.mx_6quad_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6quadplus_firmware cpe:2.3:o:nxp:i.mx_6quadplus_firmware:-:*:*:*:*:*:*:*
nxp i.mx_6dualplus_firmware cpe:2.3:o:nxp:i.mx_6dualplus_firmware:-:*:*:*:*:*:*:*
nxp i.mx_28_firmware cpe:2.3:o:nxp:i.mx_28_firmware:-:*:*:*:*:*:*:*
nxp i.mx_7dual_firmware cpe:2.3:o:nxp:i.mx_7dual_firmware:-:*:*:*:*:*:*:*
nxp i.mx_7solo_firmware cpe:2.3:o:nxp:i.mx_7solo_firmware:-:*:*:*:*:*:*:*

References for CVE-2017-7932

URL Tags
http://www.securityfocus.com/bid/99966 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-152-02 Third Party Advisory US Government Resource VDB Entry
cvelogic Threat Intelligence