IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Mitre reveals ten worst hardware security weaknesses in 2021

The list aims to highlight common hardware flaws to help eliminate them from product development cycles

Computer hardware

Mitre has revealed its top-ten list of security vulnerabilities in hardware in a bid to help companies design more secure products.

The weaknesses highlighted in the list can be found in hardware design, architecture, or programming. Mitre compiled the list in conjunction with the Hardware CWE Special Interest Group (SIG)

Mitre publishes the Common Weakness Enumeration (CWE) for software bugs in conjunction with the US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). This marks the first time the organization has done the same thing for hardware.

The list aims to drive awareness of common hardware weaknesses through CWE and “prevent hardware security issues at the source by educating designers and programmers on how to eliminate important mistakes early in the product development lifecycle”.

"Security analysts and test engineers can use the list in preparing plans for security testing and evaluation. Hardware consumers could use the list to help them to ask for more secure hardware products from their suppliers. Finally, managers and CIOs can use the list as a measuring stick of progress in their efforts to secure their hardware and ascertain where to direct resources to develop security tools or automation processes that mitigate a wide class of vulnerabilities by eliminating the underlying root cause," Mitre said. 

The list, which is in no order, includes vulnerabilities found in many types of hardware. For example, CWE-1189 is a flaw on a system-on-a-chip (SoC) that does not properly isolate shared resources between trusted and untrusted agents.

“Several resources on the chip may be shared to multiplex and support different features or functions. When such resources are shared between trusted and untrusted agents, untrusted agents may be able to access the assets intended to be accessed only by the trusted agents,” Mitre noted. 

Another hardware bug mentioned on the list is where a chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

“If authorization, authentication, or some other form of access control is not implemented or not implemented correctly, a user may be able to bypass on-chip protection mechanisms through the debug interface,” said Mitre.

It added that the methodology used to generate the inaugural CWE Most Important Hardware Weaknesses List is “limited somewhat in terms of scientific and statistical rigor.”

"In the absence of more relevant data from which to conduct systematic inquiry, the list was compiled using a modified Delphi method leveraging subjective opinions, albeit from informed content knowledge experts,” it added.

Featured Resources

How to hold more productive meetings

Tips and tricks to get the most out of your meetings

Free Download

Enabling the future of work with embedded real-time communication

A new dimension of human interaction is coming to digital work

Free Download

How to do hybrid work right

Overcoming challenges in the transition to hybrid work

Watch now

HCI 2.0 From HPE: How it can help your business thrive

Why SMBs need to accelerate digital transformation with HCI

Free download

Recommended

Selecting a fit-for-purpose server platform for datacentre infrastructure
Whitepaper

Selecting a fit-for-purpose server platform for datacentre infrastructure

21 Mar 2022
Modernise your server infrastructure for speed and security
Whitepaper

Modernise your server infrastructure for speed and security

9 Feb 2022
Modernise your server infrastructure for speed and security
Whitepaper

Modernise your server infrastructure for speed and security

9 Feb 2022
The best deals on web hosting this Black Friday
web hosting

The best deals on web hosting this Black Friday

26 Nov 2021

Most Popular

Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
How full-stack observability can accelerate IT innovation
Sponsored

How full-stack observability can accelerate IT innovation

3 May 2022