CVE-2025-51675
openRISC · OR1200
A flaw in the openRISC OR1200 processor architecture allows for a denial of service due to inaccurate program counter updates during special purpose register changes.
Executive summary
A high-severity denial of service vulnerability exists within the openRISC OR1200 processor architecture that may allow remote attackers to crash affected systems.
Vulnerability
The vulnerability is caused by an inaccurate update of program counter values when special purpose registers are modified. This flaw is remotely exploitable without authentication, potentially leading to a complete service disruption.
Business impact
The ability for an unauthenticated attacker to trigger a denial of service condition poses a significant risk to operational continuity. Given the CVSS score of 7.5, this vulnerability could be leveraged to take critical infrastructure or embedded systems offline, resulting in substantial service downtime and potential loss of availability for dependent business processes.
Remediation
Immediate Action: Organizations utilizing the openRISC OR1200 architecture should review their current commit levels and investigate vendor-provided updates or patches to address the program counter update flaw.
Proactive Monitoring: Security teams should monitor system logs for frequent, unexplained system resets or performance degradation that may indicate an ongoing denial of service attempt.
Compensating Controls: While direct patching is the primary defense, implementing network-level traffic filtering and rate limiting may reduce the potential for remote exploitation of this flaw.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the remote exploitability and the potential for total system unavailability, this vulnerability should be treated with high priority. Users of the affected openRISC hardware must track upstream repository updates for a fix regarding commit 83ac6b and apply relevant firmware or microcode updates as soon as they become available.