CVE-2024-38433
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
11/07/2024
Last modified:
15/07/2024
Description
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness<br />
<br />
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock<br />
<br />
reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code<br />
<br />
execution.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:nuvoton:npcm750r_firmware:*:*:*:*:*:*:*:* | 10.10.19 (excluding) | |
cpe:2.3:h:nuvoton:npcm750r:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:nuvoton:npcm710r_firmware:*:*:*:*:*:*:*:* | 10.10.19 (excluding) | |
cpe:2.3:h:nuvoton:npcm710r:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:nuvoton:npcm730r_firmware:*:*:*:*:*:*:*:* | 10.10.19 (excluding) | |
cpe:2.3:h:nuvoton:npcm730r:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:nuvoton:npcm705r_firmware:*:*:*:*:*:*:*:* | 10.10.19 (excluding) | |
cpe:2.3:h:nuvoton:npcm705r:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page