Renesas is an embedded and automotive semiconductor vendor whose vulnerability footprint concentrates in system firmware and bootloader components, particularly ARM Trusted Firmware variants and the R-Car automotive system-on-chip family. The recurring weakness classes center on memory-safety and arithmetic issues—buffer overflows, integer overflows and underflows, and calculation errors—that are typical of low-level firmware codebases where bounds-checking and type safety fall to manual implementation. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Renesas over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6287HIGH Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code.
When checking whether a new image invades/overlaps with a previously loaded im | Jun 24, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-6564MEDIUM Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead | Jul 8, 2024 | 6.7 | 19 | NO | NO |
CVE-2024-6563MEDIUM Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associate | Jul 8, 2024 | 6.7 | 19 | NO | NO |
CVE-2024-6285MEDIUM Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware.
An integer underflow in image range check calculations could lead to bypassing address restric | Jun 24, 2024 | 6.7 | 19 | NO | NO |
CVE-2021-43327MEDIUM An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID key from the device. Then, the protected firmware can be extra | Dec 2, 2021 | 4.6 | 19 | NO | NO |
During the secure boot, bl2 (the second stage of
the bootloader) loops over images defined in the table “bl2_mem_params_descs”.
For each image, the bl2 reads the image length and d | Feb 19, 2024 | 2.0 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Renesas.
Media articles that mention a CVE ID that affects a product developed by Renesas — matched by CVE ID, not by vendor name.