CVE-2026-11836
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set.
This issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Caliptra | Core ROM | 2.0.0 <= 2.0.2 | affected |
| Caliptra | Core ROM | 2.0.3 | unaffected |
| Caliptra | Core ROM | 2.1.0 <= 2.1.1 | affected |
| Caliptra | Core ROM | 2.1.2 | unaffected |
| Caliptra | Core Firmware | 2.0.0 <= 2.0.1 | affected |
| Caliptra | Core Firmware | 2.0.2 | unaffected |
| Caliptra | Core Firmware | 2.1.0 | affected |
| Caliptra | Core Firmware | 2.1.1 | unaffected |
Weaknesses
- CWE-345: CWE-345 Insufficient Verification of Data Authenticity
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.