CVE-2024-32633: Unsigned compared against 0
Published Apr 16, 2024
·Updated
An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.
Affected Software
26 affected components
All of the following
Asrmicro Asr1803sc Firmware<cp01.057.067
Asrmicro Asr1803sc
All of the following
Asrmicro Asr1607 Firmware<cp01.057.067
Asrmicro Asr1607
All of the following
Asrmicro Asr3603 Firmware<cp01.057.067
Asrmicro Asr3603
All of the following
Asrmicro Asr3602 Firmware<cp01.057.067
Asrmicro Asr3602
All of the following
Asrmicro Asr3605 Firmware<cp01.057.067
Asrmicro Asr3605
All of the following
Asrmicro Asr3607 Firmware<cp01.057.067
Asrmicro Asr3607
All of the following
Asrmicro Asr1609 Firmware<cp01.057.067
Asrmicro Asr1609
All of the following
Asrmicro Asr1605 Firmware<cp01.057.067
Asrmicro Asr1605
All of the following
Asrmicro Asr1602 Firmware<cp01.057.067
Asrmicro Asr1602
All of the following
Asrmicro Asr1603 Firmware<cp01.057.067
Asrmicro Asr1603
All of the following
Asrmicro Asr1606 Firmware<cp01.057.067
Asrmicro Asr1606
All of the following
Asrmicro Asr1803 Firmware<cp01.057.067
Asrmicro Asr1803
All of the following
Asrmicro Asr1806 Firmware<cp01.057.067
Asrmicro Asr1806
Event History
Apr 16, 2024
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32633?
CVE-2024-32633 is classified with a severity that can potentially lead to inaccurate eMMC full disk tests due to the handling of unsigned values.
2
How do I fix CVE-2024-32633?
To mitigate CVE-2024-32633, ensure that your device firmware is updated to a version beyond cp01.057.067.
3
Which Asrmicro devices are affected by CVE-2024-32633?
CVE-2024-32633 affects various Asrmicro firmware versions for devices like Asr1602, Asr1603, Asr1803, and others up to version cp01.057.067.
4
What can happen if CVE-2024-32633 is exploited?
Exploitation of CVE-2024-32633 may result in misleading results during full disk tests on affected eMMC devices.
5
Is CVE-2024-32633 a confirmed vulnerability?
Yes, CVE-2024-32633 has been confirmed as a vulnerability in specific versions of Asrmicro firmware.