CAPEC Definitions

    CAPEC Definitions / CAPEC-680

    CAPEC-680: Exploitation of Improperly Controlled Registers

    An adversary exploits missing or incorrectly configured access control within registers to read/write data that is not meant to be obtained or modified by a user.

    Severity:High
    Possibility:Medium

    Extended Description

    Hardware systems often utilize trusted lock bits to prevent a set of registers from being written to or to restrict a register to only being written to once. Registers are also frequently used to store sensitive data leveraged in additional security operations, such as secure booting, authenticating code, device attestation, and more. However, the access control mechanisms meant to protect these registers may be fully missing or ineffective due to misconfiguration. If an adversary is able to discover improper access controls surrounding registers, it could result in the adversary obtaining sensitive data and/or modifying data that is meant to be immutable. This can ultimately result in processes like secure boot being circumvented or in protected configurations being modified.

    Mitigations

    Design proper access control policies for hardware register access from software and ensure these policies are implemented in accordance with the specified design.

    Ensure security lock bit protections are reviewed for design inconsistencies and common weaknesses.

    Test security lock programming flow in both pre-silicon and post-silicon environments.

    Leverage automated tools to test that values are not reprogrammable and that write-once fields lock on writing zeros.

    Ensure that measurement data is stored in registers that are read-only or otherwise have access controls that prevent modification by an untrusted agent.

    Relationships with other CAPECs

    CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs

    CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels

    Prerequisites

    Awareness of the hardware being leveraged.

    Access to the hardware being leveraged.

    Related Weaknesses

    CWE-1224: Improper Restriction of Write-Once Bit Fields

    CWE-1231: Improper Prevention of Lock Bit Modification

    CWE-1233: Security-Sensitive Hardware Controls with Missing Lock Bit Protection

    CWE-1262: Improper Access Control for Register Interface

    CWE-1283: Mutable Attestation or Measurement Reporting Data