Nuvoton manufactures embedded microcontrollers and system-management firmware used in server, industrial, and IoT appliances, with disclosures concentrating in its NPCT75x and NPCM7xx product families. The durable signal across these components centers on authentication and authorization weaknesses, including authentication bypass, improper credential validation, missing authorization checks, and observable discrepancies that expose management interfaces and sensitive operations to unauthorized access. Current vulnerability counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuvoton over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38433MEDIUM Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock
reference | Jul 11, 2024 | 6.7 | 19 | NO | NO |
CVE-2021-32015MEDIUM In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: | Jun 8, 2021 | 6.0 | 19 | NO | NO |
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel | Aug 10, 2021 | 3.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuvoton.
Media articles that mention a CVE ID that affects a product developed by Nuvoton — matched by CVE ID, not by vendor name.