CWE-1274Base

Improper Access Control for Volatile Memory Containing Boot Code

Stable in the CWE catalog · 7 CVEs mapped

7
CVEs mapped
7.1
Median CVSS
What it is

The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.

Recent examples
4.6cvss
CVE-2024-36345

Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read…

Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.

MEDIUMno explanation yet
0%
epss
7.1cvss
CVE-2025-29950

Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution

Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution.

HIGHno explanation yet
0%
epss
6.8cvss
CVE-2025-59694

CVE-2025-59694 - MEDIUM Severity Vulnerability

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1274
Abstraction
Base
Structure
Simple
Status
Stable