Cva6
Vendor:
First CVE: Jun 29, 2022 · Active for 4 years
10
Total CVEs
More Total CVEs than 89% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cva6 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2022
4 years ago
Most Recent CVE
Jul 18, 2022
1,471 days ago
CVE Severity & Scoring
Cva610 CVEs
70%
20%
10%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (70.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34635CRITICAL The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty. | Jul 18, 2022 | 9.8 | 26 | NO | NO |
CVE-2022-33023HIGH CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong. | Jun 29, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-34641MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occ | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34639MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34637MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34636MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occ | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34634MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-33021HIGH CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30. | Jun 29, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-34640MEDIUM The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect. | Jul 18, 2022 | 5.5 | 18 | NO | NO |
CVE-2022-34633MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception. | Jul 18, 2022 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Cva6
Top CWEs
Versions
No cataloged versions.