PT-2024-37514 · Renesas+1 · Arm Trusted Firmware+1
Tomer Fichman
·
Published
2024-06-24
·
Updated
2024-12-20
·
CVE-2024-6287
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Renesas arm-trusted-firmware (affected versions not specified)
Description:
The issue arises from an incorrect calculation in the code that checks for image overlap with previously loaded images. This oversight allows an attacker to bypass memory range restrictions, potentially overwriting an already loaded image partly or completely. As a result, this could lead to code execution and bypass of secure boot mechanisms.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Arm Trusted Firmware