Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openhwgroup

First CVE: Jun 29, 2022Active for: 4 yearsTotal CVEs: 10
24.0
VTI Score
Low

Openhwgroup's vulnerability profile centers on the CVA6 processor core, an open-source RISC-V design that occupies a specialized but strategically important position in the processor landscape as a reference and integration target for custom silicon implementations. The recurring weakness classes—improper exception handling, default permission issues, and boundary-condition weaknesses—reflect the architectural and configuration complexities inherent in CPU design and hardware description language codebases. Defenders working with custom or embedded processors derived from CVA6 should review disclosed issues against their integration points and toolchains; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
10.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openhwgroup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2022
4 years ago
Most Recent CVE
Jul 18, 2022
1,467 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34635CRITICAL
The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty.
Jul 18, 20229.826NONO
CVE-2022-33023HIGH
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
Jun 29, 20227.524NONO
CVE-2022-34641MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occ
Jul 18, 20225.519NONO
CVE-2022-34639MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.
Jul 18, 20225.519NONO
CVE-2022-34637MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.
Jul 18, 20225.519NONO
CVE-2022-34636MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occ
Jul 18, 20225.519NONO
CVE-2022-34634MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.
Jul 18, 20225.519NONO
CVE-2022-33021HIGH
CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.
Jun 29, 20227.519NONO
CVE-2022-34640MEDIUM
The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect.
Jul 18, 20225.518NONO
CVE-2022-34633MEDIUM
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.
Jul 18, 20225.516NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
70%
20%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (70.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openhwgroup.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openhwgroup — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openhwgroup's Products

View all 1 CNAs →

Top CWEs