CVE-2024-13942
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD).
The code reads the header of the next-stage loader twice. The header contains hashes of the executable modules and is signed with a private key, the public part of which is verified against the SHA256 digest blown in the OTP.
The first read is only partial and contains only the hashes of the executable modules. The second is complete, including the header signature.
Although the header is verified based on the fully read data, the authenticity of the executable modules is checked against the partial data from the first read.
Leer descripción completaMostrar menos
An attacker with physical access to a device containing RK3588s SoC can easily modify the next-stage loader data on-the-fly using a low-cost SD-card or SPI NOR/NAND or EMMC emulator. Even a simple ultra low-cost circuit comprising two memory chips (containing the same data but different headers - the original and the modified one) and a multiplexer can be used to carry out an attack.
This can lead to arbitrary code execution with the highest privileges available (EL3). This issue affects RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. As remediation apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 7.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1091Replication Through Removable Medialateral movement · initial access95 % - Impacto principal
T1068Exploitation for Privilege Escalationprivilege escalation90 % - Impacto secundario
T1059Command and Scripting Interpreterexecution85 %
Acceso físico a dispositivo (AV:P) con manipulación de medios extraíbles (SD, SPI NOR, NAND, EMMC). Logra ejecución de código arbitrario en EL3 (escalada de privilegios máximos) mediante race condition TOCTOU en BootROM.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-367
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-13942",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-13942",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-19T19:08:57.606738Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vulnerability@kaspersky.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "PHYSICAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "vulnerability@kaspersky.com",
"affectedData": [
{
"vendor": "Rockchip",
"modules": [
"Secure BootROM"
],
"product": "RK3588s",
"versions": [
{
"status": "affected",
"version": "350B20210512V100"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-08-19T17:18:21.440",
"references": [
{
"url": "https://github.com/klsecservices/Advisories/blob/master/KLSA-00230-Rockchip-RK3588s-Secure-BootROM-TOCTOU-vulnerability.md",
"source": "vulnerability@kaspersky.com"
},
{
"url": "https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html",
"source": "vulnerability@kaspersky.com"
},
{
"url": "https://www.rock-chips.com/a/en/psirt/vdp.html",
"source": "vulnerability@kaspersky.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerability@kaspersky.com",
"description": [
{
"lang": "en",
"value": "CWE-367"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD).\n\n\n\n\nThe code reads the header of the next-stage loader twice. The header contains hashes of the executable modules and is signed with a private key, the public part of which is verified against the SHA256 digest blown in the OTP.\n\n\n\n\nThe first read is only partial and contains only the hashes of the executable modules. The second is complete, including the header signature.\n\nAlthough the header is verified based on the fully read data, the authenticity of the executable modules is checked against the partial data from the first read.\n\n\n\n\nAn attacker with physical access to a device containing RK3588s SoC can easily modify the next-stage loader data on-the-fly using a low-cost SD-card or SPI NOR/NAND or EMMC emulator. Even a simple ultra low-cost circuit comprising two memory chips (containing the same data but different headers - the original and the modified one) and a multiplexer can be used to carry out an attack.\n\n\n\n\nThis can lead to arbitrary code execution with the highest privileges available (EL3). This issue affects RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others.\nAs remediation apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html"
},
{
"lang": "es",
"value": "El BootROM seguro del SoC RK3588s es vulnerable a un ataque de tiempo de verificación a tiempo de uso en caso de arranque desde medios externos (SPI NOR o NAND, EMMC o SD).\n\nEl código lee el encabezado del cargador de siguiente etapa dos veces. El encabezado contiene hashes de los módulos ejecutables y está firmado con una clave privada, cuya parte pública se verifica contra el resumen SHA256 grabado en la OTP.\n\nLa primera lectura es solo parcial y contiene solo los hashes de los módulos ejecutables. La segunda es completa, incluyendo la firma del encabezado.\n\nAunque el encabezado se verifica basándose en los datos leídos completamente, la autenticidad de los módulos ejecutables se verifica contra los datos parciales de la primera lectura.\n\nUn atacante con acceso físico a un dispositivo que contiene el SoC RK3588s puede modificar fácilmente los datos del cargador de siguiente etapa sobre la marcha utilizando un emulador de tarjeta SD o SPI NOR/NAND o EMMC de bajo costo. Incluso un circuito simple de ultra bajo costo que comprende dos chips de memoria (que contienen los mismos datos pero diferentes encabezados - el original y el modificado) y un multiplexor puede usarse para llevar a cabo un ataque.\n\nEsto puede llevar a la ejecución de código arbitrario con los privilegios más altos disponibles (EL3). Este problema afecta a RK3588s: RK3588s SoC BootROM (seguro) 350B20210512V100 y posiblemente a otros.\nComo remediación, aplique mitigaciones según las instrucciones del proveedor o descontinúe el uso del producto si las mitigaciones no están disponibles https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html"
}
],
"lastModified": "2026-10-01T23:10:00.233",
"sourceIdentifier": "vulnerability@kaspersky.com"
}