Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published: 2024-07-11T07:50:45.579Z

Updated: 2024-08-02T04:12:24.827Z

Reserved: 2024-06-16T08:00:52.285Z

Link: CVE-2024-38433

cve-icon Vulnrichment

Updated: 2024-08-02T04:12:24.827Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-11T08:15:10.623

Modified: 2024-07-15T18:26:30.693

Link: CVE-2024-38433

cve-icon Redhat

No data.