CVE-2024-30212

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
28/05/2024
Last modified:
11/06/2024

Description

If a SCSI READ(10) command is initiated via USB using the largest LBA <br /> (0xFFFFFFFF) with it&amp;#39;s default block size of 512 and a count of 1,<br /> <br /> the first 512 byte of the 0x80000000 memory area is returned to the <br /> user. If the block count is increased, the full RAM can be exposed.<br /> <br /> The same method works to write to this memory area. If RAM contains <br /> pointers, those can be - depending on the application - overwritten to<br /> <br /> return data from any other offset including Progam and Boot Flash.

Impact