The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.
Volume of CVEs assigned to CWE-1274 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2482HIGH
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible f | Jan 6, 2023 | 8.8 | 28 | NO | NO |
CVE-2025-65396MEDIUM A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootl | Jan 14, 2026 | 6.1 | 27 | NO | NO |
CVE-2025-59404HIGH Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modifi | Sep 25, 2025 | 7.5 | 26 | NO | NO |
CVE-2022-2484HIGH
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the executio | Jan 6, 2023 | 7.8 | 26 | NO | NO |
CVE-2025-29950HIGH Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution. | Feb 10, 2026 | 7.1 | 23 | NO | NO |
CVE-2025-59694MEDIUM The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify fir | Dec 2, 2025 | 6.8 | 23 | NO | NO |
CVE-2024-36345MEDIUM Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting i | May 15, 2026 | 4.6 | 22 | NO | NO |
CVE-2025-4043MEDIUM An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. | May 7, 2025 | 6.8 | 20 | NO | NO |
CVE-2023-31345HIGH Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | Feb 12, 2025 | 7.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.