Nuvoton - CWE-305: Authentication Bypass by Primary...
Moderate severity
Unreviewed
Published
Jul 11, 2024
to the GitHub Advisory Database
•
Updated Jul 15, 2024
Description
Published by the National Vulnerability Database
Jul 11, 2024
Published to the GitHub Advisory Database
Jul 11, 2024
Last updated
Jul 15, 2024
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock
reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code
execution.
References