CVE-2024-38433 – Nuvoton – CWE-305: Authentication Bypass by Primar

CVE ID : CVE-2024-38433

Published : July 11, 2024, 8:15 a.m. | 1 hour, 5 minutes ago

Description : Nuvoton – CWE-305: Authentication Bypass by Primary Weakness

An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock

reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code

execution.

Severity: 6.7 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…CVE ID : CVE-2024-38433

Published : July 11, 2024, 8:15 a.m. | 1 hour, 5 minutes ago

Description : Nuvoton – CWE-305: Authentication Bypass by Primary Weakness

An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock

reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code

execution.

Severity: 6.7 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…