CVE-2024-33660
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-33660 is a newly disclosed vulnerability that allows an attacker with physical access to manipulate SPI flash memory undetected. This issue can potentially result in unauthorized modification of critical system configurations or data stored in the affected device. The attacker may be able to execute arbitrary code or gain elevated privileges, leading to significant security risks. The precise impact of this vulnerability depends on the specific use case and the target system's design. However, it is crucial to note that gaining physical access is a prerequisite for exploiting this weakness. Organizations should prioritize implementing appropriate access controls and securing their hardware against unauthorized physical access to mitigate the risks associated with CVE-2024-33660.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aptio V