CVE-2024-38433

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
11/07/2024
Last modified:
15/07/2024

Description

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness<br /> <br /> An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock<br /> <br /> reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code<br /> <br /> execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nuvoton:npcm750r_firmware:*:*:*:*:*:*:*:* 10.10.19 (excluding)
cpe:2.3:h:nuvoton:npcm750r:-:*:*:*:*:*:*:*
cpe:2.3:o:nuvoton:npcm710r_firmware:*:*:*:*:*:*:*:* 10.10.19 (excluding)
cpe:2.3:h:nuvoton:npcm710r:-:*:*:*:*:*:*:*
cpe:2.3:o:nuvoton:npcm730r_firmware:*:*:*:*:*:*:*:* 10.10.19 (excluding)
cpe:2.3:h:nuvoton:npcm730r:-:*:*:*:*:*:*:*
cpe:2.3:o:nuvoton:npcm705r_firmware:*:*:*:*:*:*:*:* 10.10.19 (excluding)
cpe:2.3:h:nuvoton:npcm705r:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools