CWE-1209: Failure to Disable Reserved Bits
The reserved bits in a hardware design are not disabled prior to production. Typically, reserved bits are used for future capabilities and should not support any functional logic in the design. However, designers might covertly use these bits to debug or further develop new capabilities in production hardware. Adversaries with access to these bits will write to them in hopes of compromising hardware state.
How it's found
Failure to Disable Reserved Bits is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
Reserved bits are labeled as such so they can be allocated for a later purpose. They are not to do anything in the current design. However, designers might want to use these bits to debug or control/configure a future capability to help minimize time to market (TTM). If the logic being controlled by these bits is still enabled in production, an adversary could use the logic to induce unwanted/unsupported behavior in the hardware.
Vulnerable vs. safe
gpio_out = 1;beginend4'b1111 : //0x0Freg gpio_out = 0; //gpio should remain low for normal operationcase (register_address)//4'b1111 : //0x0Fdefault: gpio_out = gpio_out;reg gpio_out = 0; //gpio should remain low for normal operationcase (register_address)Consequences
- Varies by Context: This type of weakness all depends on the capabilities of the logic being controlled or configured by the reserved bits.
Mitigations
- Architecture and Design/Implementation: Include a feature to disable reserved bits.
- Integration: Any writes to these reserve bits are blocked (e.g., ignored, access-protected, etc.), or an exception can be asserted.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is CWE-1209?
The reserved bits in a hardware design are not disabled prior to production. Typically, reserved bits are used for future capabilities and should not support any functional logic in the design. However, designers might covertly use these bits to debug or further develop new capabilities in production hardware. Adversaries with access to these bits will write to them in hopes of compromising hardware state.
How do you find Failure to Disable Reserved Bits?
Failure to Disable Reserved Bits is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-1209?
Varies by Context: This type of weakness all depends on the capabilities of the logic being controlled or configured by the reserved bits.
Does TurboPentest test for Failure to Disable Reserved Bits?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related CWEs
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest