CVE-2024-7726

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Dec 20, 2024
CWE ID 306

Summary

CVE-2024-7726 is a newly discovered vulnerability affecting Kioxia's PM6, PM7, and CM6 disk drives. The issue lies in an unauthenticated accessible JTAG port on these devices. On Kioxia's CM6, PM6, and PM7 drives, the main CPU cores of the SoC can be accessed via this open JTAG debug port, which is exposed on the drive’s circuit board. The wide cutout of the enclosures allows an attacker with temporary physical access to reach the JTAG port without opening the disk enclosure. Exploiting this vulnerability, an attacker can gain full access to the firmware and memory on the 2 main CPU cores, enabling arbitrary code execution, manipulation of firmware execution flow, and data modification or bypassing firmware signature verification during boot-up.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share