CVE-2024-38433

CVSS V2 None CVSS V3 None
Description
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
Overview
  • CVE ID
  • CVE-2024-38433
  • Assigner
  • INCD
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-11T07:50:45.579Z
  • Last Modified Date
  • 2024-07-11T14:42:56.399Z
References
History
Created Old Value New Value Data Type Notes
2024-07-12 13:11:32 Added to TrackCVE