CVE-2024-38433: Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock
reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code
execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38433?
CVE-2024-38433 has not been assigned a specific severity score, but it involves an authentication bypass vulnerability that could lead to serious security implications.
What systems are affected by CVE-2024-38433?
CVE-2024-38433 affects Nuvoton NPCM7xx BMC subsystems running specific versions of Nuvoton firmware prior to 10.10.19.
How do I fix CVE-2024-38433?
To mitigate CVE-2024-38433, update to the latest firmware version that is above 10.10.19 for the affected Nuvoton NPCM7xx systems.
What kind of attack does CVE-2024-38433 allow?
CVE-2024-38433 allows an attacker with write access to the SPI-Flash to modify critical parts of the system, potentially resulting in arbitrary code execution.
Who can exploit CVE-2024-38433?
An attacker with physical write access to the SPI-Flash memory of the affected Nuvoton BMC subsystem can exploit CVE-2024-38433.