CWE-1223: Race Condition for Write-Once Attributes

low-risk

A write-once register in hardware design is programmable by an untrusted software component earlier than the trusted software component, resulting in a race condition issue.

Abstraction: Base

Common Consequences

Access Control Bypass Protection Mechanism

Detection Methods

Automated Analysis

The testing phase should use automated tools to test that values are not reprogrammable and that write-once fields lock on writing zeros.

Real-World Examples (2)

CVE CVSS EPSS KEV
CVE-2024-2975 8.8 0.4%
CVE-2025-0077 4.0 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal