Home
MEDIUM: 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
All versions (custom) before v10.10.19
affected
Description
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
Problem types
CWE-305: Authentication Bypass by Primary Weakness
Product status
All versions (custom) before v10.10.19
Credits
Ferdinand Nölscher of Google's OTS-HS Team
References
www.gov.il/en/Departments/faq/cve_advisories
www.gov.il/en/Departments/faq/cve_advisories