CWE-327: Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
Browse cwe for verilog with official CWE context and Glexia analysis.
Search And Filters
Showing 15 of 15 CWE records.
The product uses a broken or risky cryptographic algorithm or protocol.
Hardware description language code incorrectly defines register defaults or hardware Intellectual Property (IP) parameters to insecure values.
A write-once register in hardware design is programmable by an untrusted software component earlier than the trusted software component, resulting in a race condition issue.
The hardware design control register "sticky bits" or write-once bit fields are improperly implemented, such that they can be reprogrammed by software.
The product's architecture mirrors regions without ensuring that their contents always stay in sync.
The product released to market is released in pre-production or manufacturing configuration.
The product performs a power or debug state transition, but it does not clear sensitive information that should no longer be accessible due to changes to information access restrictions.
The credentials necessary for unlocking a device are shared across multiple parties and may expose sensitive information.
Performing cryptographic operations without ensuring that the supporting inputs are ready to supply valid data may compromise the cryptographic result.
A product's hardware-based access control check occurs after the asset has been accessed.
The product's debug components contain incorrect chaining or granularity of debug components.
The product does not adequately protect confidential information on the device from being accessed by Outsourced Semiconductor Assembly and Test (OSAT) vendors.
A race condition in the hardware logic results in undermining security guarantees of the system.
The bridge incorrectly translates security attributes from either trusted to untrusted or from untrusted to trusted when converting from one fabric protocol to another.
The product has a hardware interface that silently discards operations in situations for which feedback would be security-relevant, such as the timely detection of failures or attacks.