Openrisc is an open-source processor architecture project whose vulnerability footprint centers on processor core implementations and firmware, particularly the MOR1KX and OR1200 designs. The durable signal across its disclosures reflects authentication and default-permission issues in embedded firmware contexts, alongside cases where vulnerability details remain limited; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openrisc over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40507CRITICAL An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract | Apr 18, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-40506CRITICAL An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instru | Apr 18, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-41612HIGH An issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly for the subtract instruction, which results in an incorrect | Apr 18, 2023 | 8.8 | 28 | NO | NO |
CVE-2021-41614HIGH An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter Register (EPCR) are not implemen | Apr 18, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-41613MEDIUM An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective Address Register (EEAR) is not implemented correctly. User p | Apr 18, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openrisc.
Media articles that mention a CVE ID that affects a product developed by Openrisc — matched by CVE ID, not by vendor name.