Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update.
This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. | |
| Title | MCU Firmware Update Authentication Bypass on Caliptra Core | |
| Weaknesses | CWE-253 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Caliptra
Published:
Updated: 2026-06-23T23:50:06.556Z
Reserved: 2026-04-08T15:45:10.928Z
Link: CVE-2026-5818
No data.
No data.
No data.
OpenCVE Enrichment
No data.