CVE-2024-25077: Code Injection
An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in an unsigned header, allowing its value to be modified without invalidating the signature used for secureboot image verification. Because the encryption engine for on-the-fly decryption uses AES in CTR mode without authentication, an attacker-modified Nonce can result in execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25077?
CVE-2024-25077 has been classified as a critical vulnerability due to its potential impact on device security.
How do I fix CVE-2024-25077?
To mitigate CVE-2024-25077, it’s recommended to apply the latest firmware updates provided by Renesas for affected SmartBond devices.
Which devices are affected by CVE-2024-25077?
CVE-2024-25077 affects the Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices.
What are the risks associated with CVE-2024-25077?
The risks associated with CVE-2024-25077 include unauthorized modification of on-the-fly decryption parameters, potentially leading to execution of malicious code.
Is there a workaround for CVE-2024-25077?
While firmware updates are the primary fix, limiting physical access to devices may help reduce the risk associated with CVE-2024-25077.