Products
arm-trusted-firmware
Source
cve@asrg.io
Tags
CVE-2024-6287 details
Published : June 24, 2024, 4:15 p.m.
Last Modified : June 24, 2024, 7:26 p.m.
Last Modified : June 24, 2024, 7:26 p.m.
Description
Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7.5 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-682 | Incorrect Calculation | The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management. |
CVSS Data
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
7.5
Exploitability Score
0.8
Impact Score
6.0
Base Severity
HIGH
Vector String : CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
References
URL | Source |
---|---|
https://asrg.io/security-advisories/cve-2024-6287/ | cve@asrg.io |
https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04 | cve@asrg.io |
This website uses the NVD API, but is not approved or certified by it.