CVE-2021-40507
Last modified
CVE-2021-40507 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openrisc | Or1200 Firmware | >= 2011-09-10, <= 2015-11-11 |
References
- https://seth.engr.tamu.edu/software-releases/thehuzz/Third Party Advisory
- https://seth.engr.tamu.edu/software-releases/thehuzz/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40507?
How severe is CVE-2021-40507?
How do I fix CVE-2021-40507?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-40500SAP BusinessObjects Business Intelligence Platform (Crystal …7.5
- CVE-2021-40501SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, …8.1
- CVE-2021-40502SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, d…8.8
- CVE-2021-40503An information disclosure vulnerability exists in SAP GUI fo…7.8
- CVE-2021-40504A certain template role in SAP NetWeaver Application Server …4.9
- CVE-2021-40506An issue was discovered in the ALU unit of the OR1200 (aka O…9.8
- CVE-2021-40509ViewCommon.java in JForum2 2.7.0 allows XSS via a user signa…5.4
- CVE-2021-40510XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows…7.5
- CVE-2021-40511OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansi…7.5
- CVE-2021-40516WeeChat before 3.2.1 allows remote attackers to cause a deni…7.5
- CVE-2021-40517Airangel HSMX Gateway devices through 5.2.04 is vulnerable t…5.4
- CVE-2021-40518Airangel HSMX Gateway devices through 5.2.04 allow CSRF.6.5
Are you affected by CVE-2021-40507?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
