PT-2024-38535 · Kioxia · Kioxia Pm6+2
Mkammerstetter
·
Published
2024-12-20
·
Updated
2025-07-23
·
CVE-2024-7726
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kioxia PM6, PM7, and CM6 devices (affected versions not specified)
Description
The issue concerns an unauthenticated accessible JTAG port on the Kioxia PM6, PM7, and CM6 devices. This port is exposed on the drive's circuit board and can be accessed without opening the disk enclosure due to the wide cutout of the enclosures. An attacker with temporary physical access can utilize the JTAG debug port to get full access to the firmware and memory on the 2 main CPU cores within the drive. This access includes the execution of arbitrary code, the modification of firmware execution flow and data, or bypassing the firmware signature verification during boot-up.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kioxia Cm6
Kioxia Pm6
Kioxia Pm7