CVE-2024-6287 is an Incorrect Calculation vulnerability in Renesas arm-trusted-firmware, specifically affecting the rcar_gen3 product line. This flaw allows a local attacker to bypass memory range restrictions by neglecting certain cases when checking for image overlaps, potentially overwriting loaded images. Rated 7.8 HIGH on CVSS, a successful exploit could lead to local code execution and a bypass of secure boot mechanisms. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v2.5CPE matchmatch criteria | cpe:2.3:a:renesas:rcar_gen3:v2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.