CVE-2024-6287
Estado: ModificadaAlta (7.8)—
Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code.
When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-682
- CWE-682
Referencias
- https://asrg.io/security-advisories/cve-2024-6287/
- https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04
- https://asrg.io/security-advisories/cve-2024-6287/
- https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-6287",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-6287",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-19T13:40:09.697215Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@asrg.io",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@asrg.io",
"affectedData": [
{
"repo": "https://github.com/renesas-rcar/arm-trusted-firmware/",
"vendor": "Renesas",
"product": "rcar_gen3_v2.5",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "954d488a9798f8fda675c6b57c571b469b298f04",
"status": "unaffected"
}
],
"version": "6a96c18c474e6339fab93f54d52aa7dcc4b70e52",
"lessThan": "954d488a9798f8fda675c6b57c571b469b298f04",
"versionType": "git"
}
],
"packageName": "arm-trusted-firmware",
"programFiles": [
"https://github.com/renesas-rcar/arm-trusted-firmware/blob/rcar_gen3_v2.5/drivers/renesas/common/io/io_rcar.c"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:renesas:rcar_gen3_firmware:v2.5:*:*:*:*:*:*:*"
],
"vendor": "renesas",
"product": "rcar_gen3_firmware",
"versions": [
{
"status": "affected",
"version": "v2.5"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-06-24T16:15:11.003",
"references": [
{
"url": "https://asrg.io/security-advisories/cve-2024-6287/",
"tags": [
"Third Party Advisory"
],
"source": "cve@asrg.io"
},
{
"url": "https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04",
"tags": [
"Patch"
],
"source": "cve@asrg.io"
},
{
"url": "https://asrg.io/security-advisories/cve-2024-6287/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/renesas-rcar/arm-trusted-firmware/commit/954d488a9798f8fda675c6b57c571b469b298f04",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@asrg.io",
"description": [
{
"lang": "en",
"value": "CWE-682"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-682"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code.\n\n\nWhen checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot."
},
{
"lang": "es",
"value": "La vulnerabilidad de cálculo incorrecto en Renesas arm-trusted-firmware permite la ejecución local de código. Al comprobar si una nueva imagen invade/se superpone con una imagen previamente cargada, el código omite considerar algunos casos. Esto podría permitir a un atacante eludir la restricción del rango de memoria y sobrescribir parcial o completamente una imagen ya cargada, lo que podría provocar la ejecución del código y la omisión del arranque seguro."
}
],
"lastModified": "2026-06-17T08:17:42.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:renesas:rcar_gen3:v2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61D55B7B-8BDE-4855-914D-62371B0354CC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@asrg.io"
}