CVE-2024-38433: Nuvoton NPCM705R Firmware

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.

Affected products

  • Nuvoton NPCM705R Firmware: before 10.10.19 (fixed in 10.10.19)
  • Nuvoton NPCM710R Firmware: before 10.10.19 (fixed in 10.10.19)
  • Nuvoton NPCM730R Firmware: before 10.10.19 (fixed in 10.10.19)
  • Nuvoton NPCM750R Firmware: before 10.10.19 (fixed in 10.10.19)

Published 2024-07-11. Last modified 2026-06-17.