CVE-2024-38433

6.7MEDIUM

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the

Publicado: 7/11/2024Atualizado: 11/21/2024

Descrição

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.

Análise IADesenvolvido por IA

Produtos Afetados

nuvotonnpcm750r_firmware
nuvotonnpcm750r
-
nuvotonnpcm710r_firmware
nuvotonnpcm710r
-
nuvotonnpcm730r_firmware
nuvotonnpcm730r
-
nuvotonnpcm705r_firmware
nuvotonnpcm705r
-

Referências