CVE-2025-51677
9.1OpenRISC · OR1200 CPU
A hardware design flaw in the OpenRISC OR1200 CPU exists where an output mismatch between the RTL and the netlist can cause undefined system behavior.
Executive summary
A critical hardware design vulnerability in the OpenRISC OR1200 CPU, specifically in commit 83ac6b, may allow for unauthorized system integrity compromise and denial of service.
Vulnerability
The vulnerability stems from a mismatch between the Register Transfer Level (RTL) and the synthesized netlist of the OR1200 CPU output port. This flaw permits unauthenticated network-based attackers to potentially trigger integrity or availability failures without requiring user interaction.
Business impact
The CVSS score of 9.1 reflects the critical nature of this flaw, as it allows for severe impacts to system integrity and availability. Successful exploitation could lead to unpredictable hardware behavior, potentially causing system crashes, data corruption, or the bypass of security controls implemented at the hardware level.
Remediation
Immediate Action: Organizations utilizing the OR1200 CPU core must review their hardware implementation against the affected commit 83ac6b and coordinate with the OpenRISC project for official hardware patches or updated netlist configurations.
Proactive Monitoring: Monitor system logs for unexplained hardware resets, kernel panics, or irregular CPU behavior that may indicate successful exploitation of the underlying hardware logic.
Compensating Controls: Implement strict network segmentation and hardware-level monitoring to isolate affected systems from untrusted network traffic, thereby reducing the exposure of the CPU output ports.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity of this vulnerability and its potential to compromise the fundamental operation of the processor, it is imperative that engineering and security teams prioritize a hardware audit. Users should track the OpenRISC project for official guidance on mitigation, as hardware-level flaws cannot be resolved through standard software-based security updates.