Browse Definitions :
Definition

hardware vulnerability

A hardware vulnerability is an exploitable weakness in a computer system that enables attack through remote or physical access to system hardware.

Any means by which code can be introduced to a computer is inherently a hardware vulnerability. That means that when a user installs software, moves files such as CD/DVD ROMs or plugs in flash drives those items can all be thought of as hardware vulnerabilities, as can interfaces on the board by which the drives are connected. Securing physical access by locking any rooms, cabinets and cases housing computer equipment protects against this type of vulnerability. 

Another type of hardware vulnerability is an unexpected flaw in operation that allows attackers to gain control of a system by elevating privileges or executing code. These vulnerabilities can sometimes be exploited remotely, rather than requiring physical access. 

One such exploit, Rowhammer, works by repeatedly rewriting memory in the same addresses to allow retrieval of data from nearby address memory cells – even if the cells are protected. While this is not supposed to happen, it can and does due to hardware flaws that are hard to prevent. Google Project Zero researcher Mark Seaborn and reverse engineer Thomas Dullien detailed two proof-of-concept (POC) attacks exploiting Rowhammer.  As they explained, repeatedly accessing a row of memory can cause bit flips in adjacent rows of some DRAM devices.

Hardware vulnerabilities are not generally exploited through random hacking attempts but more typically in targeted attacks of known high-value systems and organizations. For most users, traditional malware protection and a locked door are sufficient protection.

This was last updated in November 2015

Continue Reading About hardware vulnerability

SearchCompliance
  • OPSEC (operations security)

    OPSEC (operations security) is a security and risk management process and strategy that classifies information, then determines ...

  • smart contract

    A smart contract is a decentralized application that executes business logic in response to events.

  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

SearchSecurity
  • biometric verification

    Biometric verification is any means by which a person can be uniquely identified by evaluating one or more distinguishing ...

  • password

    A password is a string of characters used to verify the identity of a user during the authentication process.

  • biometrics

    Biometrics is the measurement and statistical analysis of people's unique physical and behavioral characteristics.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • change control

    Change control is a systematic approach to managing all changes made to a product or system.

  • disaster recovery (DR)

    Disaster recovery (DR) is an organization's ability to respond to and recover from an event that affects business operations.

SearchStorage
  • PCIe SSD (PCIe solid-state drive)

    A PCIe SSD (PCIe solid-state drive) is a high-speed expansion card that attaches a computer to its peripherals.

  • VRAM (video RAM)

    VRAM (video RAM) refers to any type of random access memory (RAM) specifically used to store image data for a computer display.

  • virtual memory

    Virtual memory is a memory management technique where secondary memory can be used as if it were a part of the main memory.

Close