CVE-2024-25076
CVE-2024-25076
Título es
CVE-2024-25076
Mié, 10/07/2024 – 20:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-25076
Descripción en
An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses a user-controllable size value (Length of Flash Config Section) to control a read from the QSPI device into a fixed sized buffer, resulting in a buffer overflow and execution of arbitrary code.
10/07/2024
10/07/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off
