From 3123feeace0facdf8a026ec60608323ead1d226c Mon Sep 17 00:00:00 2001 From: Neal Liu Date: Tue, 18 Aug 2026 15:26:16 +0800 Subject: [PATCH] Add SFR for ASPEED AST27x0 series Add SFR JSON and signed CoRIM CBOR for ASPEED Technology's AST27x0 BMC BootMCU ROM, audited by Tetrel Security Inc. Signed-off-by: Neal Liu --- ...2700-OCP-SAFE-Assessment_Final-Report.json | 30 ++++++++++++++++++ ...P-SAFE-Assessment_Final-Report_signed.cbor | Bin 0 -> 1299 bytes 2 files changed, 30 insertions(+) create mode 100644 Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report.json create mode 100644 Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report_signed.cbor diff --git a/Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report.json b/Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report.json new file mode 100644 index 0000000..bb9a533 --- /dev/null +++ b/Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report.json @@ -0,0 +1,30 @@ +{ + "review_framework_version": "2.0", + "device": { + "vendor": "ASPEED Technology Inc.", + "product": "AST27x0 series", + "category": "BMC BootMCU ROM", + "repo_tag": "a070c7df4d68e4b66c2a081e25b55e06d75ae476", + "fw_version": "0x3976", + "fw_hash_sha2_384": "c9a170b8fb5594aad0d1c65a214a1250b15676a33356f5f5debd6ab9b08d42019a4bf9bcd61cbe4de6329aef4e02f6e1", + "fw_hash_sha2_512": "5de39eed4b5c82520823bfe6f51359e6799e822c960e79f731d6c0c88c7c48dfcfa19679e6e059fefe23a1fa36be408a529d1dc2c38290693d07c4c811ec0f27" + }, + "audit": { + "srp": "Tetrel Security Inc.", + "methodology": "White-Box Review", + "completion_date": "2026-06-18", + "report_version": "1.0", + "scope_number": 1, + "cvss_version": "4.0", + "issues": [ + { + "title": "Recovery Mode is Possible when Disabled by OTP", + "cvss_score": "1.0", + "cvss_vector": "CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N", + "cwe": "CWE-755: Improper Handling of Exceptional Conditions", + "description": "Recovery mode is possible even when explicitly disabled by OTP settings. This applies when the device is configured to boot from either eMMC or UFS and SLI is unavailable at the time of boot device initialization. Image validation and measured boot functionality is still respected, though this issue defeats recovery policy and the ability to reduce the ROM's attack surface.", + "cve": "" + } + ] + } +} \ No newline at end of file diff --git a/Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report_signed.cbor b/Reports/ASPEED/2026/AST2700/2026-07-24_ASPEED-Technology-Inc_AST2700-OCP-SAFE-Assessment_Final-Report_signed.cbor new file mode 100644 index 0000000000000000000000000000000000000000..f790f800115dc391a7a3447e475883ed193997e5 GIT binary patch literal 1299 zcmc&!OKclO7~XN5f^ulpQWdE@G*N{Dw6@odU$J=DbrQvGoLXMnBvm=AcgOam>z&o^ z*x9Whl9yblLd5~)P?b_AQPoyLDhH%SqK^Qgg+nPIsuTomc?2O95EV&8t5(c9Z6%JJ zxa`i%|9{{2|KB_oiWBi8BX0Q$SeoUiQPMpU(Q(z|k3@q#d^aDBg2okaYs9^28ZzM(70Vu;_q&@N4ZC4CxoJ>O2${aVUYL6Tfhh)Y zsRylV&LE(L$2lPc694-{N*1H|F(0Foqc%A*~O(tMi#BZ_O_|D){6h~ zxeJr83|#%ZIb|(g8@YRTOY>IvOniU#?I%9`$bJ()|Io)5*56py^`DD{M>#3r<$>h) z@~-*Kquteb8*n#fxM{A$o83K;Fen+QT1PtgAKP-7Pm6qnmm+d0D2JmcSPX}yfXGMv zC=e=!LWmE`k&uXjk#KusmNUIsBoS7#1=B=E5F0Q<34VHAzW{ogotQNadnpngwHr62Pv&I^CROB1 z0vTM>v2_h_1N*N>0cdYbb2Nvjjua>$sir&DwC;NYG+v80-NTz{E9xPV=5gK|1D91M z;n|C<;R)`Yi%E2@+_dh%T__+=s9`Fs9{j{ZA?kL@{mXXsiD^mE5wKQ_sonzO&`*?kkFv%fY*l}pPvU(Ii? rg*Jk(c4&BLe10x*;Dz-QD|+wk>o