CWE-1274
9 CVEs • Abstraction: Base
Improper Access Control for Volatile Memory Containing Boot Code
The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.
CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality. |
Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution. |
A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This...Show more |
1Entrust 5Nshield 5c Firmware Nshield Connect Xc Base FirmwareNshield Connect Xc High Firmware+2 moreJun 17, 2026 Dec 2, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify firmware and influence the (insecurely conf...Show more |
1Flocksafety 1Bravo Compute Box Firmware Jun 17, 2026 Sep 25, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions. |
1Milesight 1Ug65 868m Ea Firmware Jun 17, 2026 May 7, 2025 6.1 MEDIUM· v4 6.8 MEDIUM· v3 N/A· v2 An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. |
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. |
1Nokia 1Asik Airscale 474021a.101 Firmware Jun 17, 2026 Jan 6, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary progr...Show more |
1Nokia 2Asik Airscale 474021a.101 Firmware Asik Airscale 474021a.102 FirmwareJun 17, 2026 Jan 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the approp...Show more |