CVE-2017-13094 describes critical flaws within the IEEE P1735 standard for encrypting electronic-design intellectual property (IP) and managing access rights. These vulnerabilities allow attackers to recover plaintext IP without the encryption key, potentially enabling hardware trojan insertion or IP modification. With a CVSS score of 7.8 (HIGH), the vulnerability presents a significant risk due to its local attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered notable community discussion and media coverage, indicating awareness of its potential impact on implementations of the P1735 standard.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| - | - | Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:-:-:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.