Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock
reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code
execution.
References
Link | Resource |
---|---|
https://www.gov.il/en/Departments/faq/cve_advisories | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2024-07-11 08:15
Updated : 2024-07-15 18:26
NVD link : CVE-2024-38433
Mitre link : CVE-2024-38433
CVE.ORG link : CVE-2024-38433
JSON object : View
Products Affected
nuvoton
- npcm710r_firmware
- npcm705r_firmware
- npcm750r_firmware
- npcm750r
- npcm730r_firmware
- npcm705r
- npcm710r
- npcm730r