CWE-1247 3 件の CVE MITRE の定義 ↗

CWE-1247: Improper Protection Against Voltage and Clock Glitches

概要

CWE-1247(Improper Protection Against Voltage and Clock Glitches)は各種脆弱性データベースや評価で用いられる弱点タイプを説明します。定義・背景・対応する CVE は以下の各セクションを参照してください。

セキュリティへの影響
セキュリティ影響:製品や文脈に依存します。CVE 記録、深刻度、MITRE の説明を参照して優先度を判断してください。

説明

The device does not contain or contains incorrectly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information or software contained on the device.

適用プラットフォーム

種別 名称 クラス 普遍性 OS / CPE
language Not Language-Specific Undetermined
operating_system Not OS-Specific Undetermined
architecture Not Architecture-Specific Undetermined
technology ICS/OT Undetermined
technology System on Chip Undetermined
technology Power Management Hardware Undetermined
technology Clock/Counter Hardware Undetermined
technology Sensor Hardware Undetermined

このデータベースの関連 CVE

これらの CVE は本データベースでこの弱点に対応付けられており、追跡と検索のために保持されています。

CVE 公開 概要
CVE-2025-54520 2025-09-24 Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss of confidentiality.
CVE-2024-4760 2024-05-16 A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to the memory bus via the debug …
CVE-2022-31224 2022-09-12 Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by trigg…

旧名称

  • Missing Protection Against Voltage and Clock Glitches (2020-08-20)
  • Missing or Improperly Implemented Protection Against Voltage and Clock Glitches (2021-10-28)

コンテンツ投稿

名称
Arun Kanuparthi, Hareesh Khattri, Parbati Kumar Manna, Narasimha Kumar V Mangipudi
組織
Intel Corporation
日付
2020-02-12
バージョン
4.0

コンテンツの変更履歴

日付 名称 バージョン 重要度 コメント
2020-08-20 CWE Content Team 4.2 updated Demonstrative_Examples, Description, Name, Observed_Examples, Potential_Mitigations, Related_Attack_Patterns
2020-12-10 CWE Content Team 4.3 updated Relationships
2021-03-15 CWE Content Team 4.4 updated Functional_Areas
2021-10-28 CWE Content Team 4.6 updated Description, Detection_Factors, Name, References, Weakness_Ordinalities
2022-04-28 CWE Content Team 4.7 updated Applicable_Platforms, Relationships
2022-06-28 CWE Content Team 4.8 updated Applicable_Platforms, Relationships
2022-10-13 CWE Content Team 4.9 updated Demonstrative_Examples, References
2023-01-31 CWE Content Team 4.10 updated Applicable_Platforms, Related_Attack_Patterns, Relationships
2023-04-27 CWE Content Team 4.11 updated References, Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2023-10-26 CWE Content Team 4.13 updated Observed_Examples
2025-09-09 CWE Content Team 4.18 updated Relationships
2025-12-11 CWE Content Team 4.19 updated Demonstrative_Examples

貢献

タイプ 名称 日付 コメント
Content Parbati K. Manna 2021-10-18 provided detection methods
cvelogic Threat Intelligence