Sceawere

Vulnerability Detail

CVE-2025-51679UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenRISC OR1200 RTL-Netlist Mismatch

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-26T21:16:37.570Z",
  "pubdate": "2026-08-26T21:16:37.570Z",
  "executiveSummary": "A structural inconsistency has been identified in the OpenRISC OR1200 processor core at commit 83ac6b, manifesting as a discrepancy between the Register Transfer Level (RTL) representation and the synthesized netlist.\nThis vulnerability involves a logic mismatch that can lead to undefined hardware behavior during execution, potentially resulting in security-critical state corruption or denial-of-service conditions.\nThe flaw affects the integrity of the processor's execution pipeline and control logic.\nThere are no specific exploitation prerequisites beyond the deployment of the affected hardware implementation, as the vulnerability is inherent to the synthesized design itself.\nThe risk implications include unpredictable processor behavior, potential privilege escalation via instruction sequence manipulation, and bypass of hardware-level security mechanisms due to desynchronized state machines.\nThis issue represents a significant supply chain integrity risk for systems utilizing this specific commit of the OR1200 core, as the physical instantiation does not faithfully reflect the intended functional specification.",
  "technicalDetails": "The vulnerability originates from a synthesis-level divergence where the hardware implementation (netlist) fails to match the logical specification defined in the RTL source code at commit 83ac6b.\nIn hardware design, RTL provides a high-level behavioral description of the circuit, which is then translated by synthesis tools into a gate-level netlist. A mismatch between these layers indicates that the optimization or mapping process has introduced logic that deviates from the original design intent.\nThe attack flow for this vulnerability is triggered by the execution of specific instruction sequences that exercise the affected logic pathways within the OR1200 core. When the CPU encounters states where the RTL and netlist logic diverge, the processor may enter an indeterminate state, execute invalid operations, or fail to adhere to defined privilege boundaries.\nAn attacker with the ability to influence software running on the OR1200 processor can craft payloads designed to probe the mismatch. By triggering these inconsistent logic gates, an attacker could force the processor to bypass internal security registers, leak data from restricted address spaces, or trigger a complete system hang/reset, effectively achieving a denial-of-service or potentially arbitrary code execution if the mismatch affects program counter or control flow logic.\nThe vulnerable component encompasses the synthesis-mapping logic within the OR1200 microarchitecture. Because this is a hardware-level flaw, the vulnerability is platform-agnostic once the silicon is fabricated or the FPGA bitstream is generated from the compromised netlist.\nPost-exploitation impact includes the loss of hardware-rooted trust, as the processor can no longer be assumed to execute instructions according to the official architecture manual. This compromises any security measures—such as memory protection units or supervisor-mode enforcement—that rely on the RTL-defined functional behavior."
}
CVE-2025-51679: OpenRISC OR1200 RTL-Netlist Mismatch (CRITICAL Severity, CVSS: 9.1) - Sceawere