PT-2024-38535 · Kioxia · Kioxia Pm6+2

Mkammerstetter

·

Published

2024-12-20

·

Updated

2025-07-23

·

CVE-2024-7726

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kioxia PM6, PM7, and CM6 devices (affected versions not specified)
Description The issue concerns an unauthenticated accessible JTAG port on the Kioxia PM6, PM7, and CM6 devices. This port is exposed on the drive's circuit board and can be accessed without opening the disk enclosure due to the wide cutout of the enclosures. An attacker with temporary physical access can utilize the JTAG debug port to get full access to the firmware and memory on the 2 main CPU cores within the drive. This access includes the execution of arbitrary code, the modification of firmware execution flow and data, or bypassing the firmware signature verification during boot-up.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-7726
GHSA-3HH8-94J4-62RH

Affected Products

Kioxia Cm6
Kioxia Pm6
Kioxia Pm7