CWE-1274: Improper Access Control for Volatile Memory Containing Boot Code
The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-29950 — Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le
- CVE-2025-4043 — Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code
- CVE-2024-36345 — Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack
Recently published
- CVE-2024-36345 — Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack
- CVE-2025-29950 — Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le
- CVE-2025-4043 — Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code