Security Advisory

CVE-2024-38433

6.7
MEDIUM

Vulnerability Description

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
Published Date July 11, 2024
Official Source NIST NVD Advisory