CVE-2024-6287

HIGH

Renesas arm-trusted-firmware - RCE

Title source: llm
STIX 2.1

Description

Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-682
Status published
Products (1)
renesas/rcar_gen3 v2.5
Published Jun 24, 2024
Tracked Since Feb 18, 2026