CVE-2024-38433: Nuvoton NPCM705R Firmware
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
Affected products
- Nuvoton NPCM705R Firmware: before 10.10.19 (fixed in 10.10.19)
- Nuvoton NPCM710R Firmware: before 10.10.19 (fixed in 10.10.19)
- Nuvoton NPCM730R Firmware: before 10.10.19 (fixed in 10.10.19)
- Nuvoton NPCM750R Firmware: before 10.10.19 (fixed in 10.10.19)
Published 2024-07-11. Last modified 2026-06-17.