CVE-2025-51679
openRISC · OR1200
A mismatch between RTL and netlist in openRISC OR1200 commit 83ac6b can lead to unexpected behavior, potentially allowing unauthorized data access or service disruption.
Executive summary
A critical RTL-to-netlist mismatch in the openRISC OR1200 architecture may allow unauthenticated remote attackers to compromise data confidentiality and system availability.
Vulnerability
This vulnerability involves a discrepancy between the Register Transfer Level (RTL) design and the resulting netlist, which can be exploited by an unauthenticated remote attacker to cause unexpected system behavior, including information disclosure and denial of service.
Business impact
The CVSS score of 9.1 reflects the critical nature of this flaw, as it is remotely exploitable without authentication or user interaction. If exploited, this could lead to the unauthorized exposure of sensitive data processed by the hardware or result in a complete system crash, causing significant operational downtime and potential security breaches in environments utilizing this core.
Remediation
Immediate Action: As no specific patch version is currently available, organizations utilizing this openRISC core should review their hardware implementation and monitor for updates via the official GitHub repository.
Proactive Monitoring: Security teams should monitor system logs for unusual behavior or performance spikes that might indicate an attempt to trigger the hardware mismatch.
Compensating Controls: Given the hardware-level nature of this flaw, implement strict network segmentation to isolate systems running the affected OR1200 core from untrusted network segments.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant security risk for systems relying on the openRISC OR1200 architecture due to the lack of required authentication for exploitation. Administrators must prioritize the verification of their hardware design versions and coordinate with their hardware supply chain to identify and apply future mitigations as they become available.