CWE-1268: Policy Privileges are not Assigned Consistently Between Control and Data Agents
The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.
How it's found
Policy Privileges are not Assigned Consistently Between Control and Data Agents is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
Integrated circuits and hardware engines may provide access to resources (device-configuration, encryption keys, etc.) belonging to trusted firmware or software modules (commonly set by a BIOS or a bootloader). These accesses are typically controlled and limited by the hardware. Hardware design access control is sometimes implemented using a policy. A policy defines which entity or agent may or may not be allowed to perform an action. When a system implements multiple levels of policies, a control policy may allow direct access to a resource as well as changes to the policies themselves. Resources that include agents in their control policy but not in their write policy could unintentionally allow an untrusted agent to insert itself in the write policy register. Inclusion in the write policy register could allow a malicious or misbehaving agent write access to resources. This action could result in security compromises including leaked information, leaked encryption keys, or modification of device configuration.
Vulnerable vs. safe
Register
Field description
AES_KEY_CONTROL_POLICY
Controls which agents can write to READ_POLICY and WRITE_POLICY registers[31:0] Default 0x00000018
AES_KEY_READ_POLICY
Controls which agents can read the AES-key registers[31:0] Default 0x00000002
AES_KEY_WRITE_POLICY
Controls which agents can write to the AES-key registers[31:0] Default 0x00000004Register
Field description
AES_KEY_CONTROL_POLICY
[31:0] Default 0x00000010
AES_KEY_READ_POLICY
[31:0] Default 0x00000002
AES_KEY_WRITE_POLICY
[31:0] Default 0x00000004Consequences
- Modify Memory, Read Memory, DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Files or Directories, Reduce Reliability
Mitigations
- Architecture and Design/Implementation: Access-control-policy definition and programming flow must be sufficiently tested in pre-silicon and post-silicon testing.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-1268?
The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.
How do you find Policy Privileges are not Assigned Consistently Between Control and Data Agents?
Policy Privileges are not Assigned Consistently Between Control and Data Agents is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-1268?
Modify Memory, Read Memory, DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Files or Directories, Reduce Reliability
Does TurboPentest test for Policy Privileges are not Assigned Consistently Between Control and Data Agents?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest