CVE-2024-7726
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open JTAG debug port that is exposed on the drive’s circuit board. Due to the wide cutout of the enclosures, the JTAG port can be accessed without having to open the disk enclosure. Utilizing the JTAG debug port, an attacker with (temporary) physical access can get full access to the firmware and memory on the 2 main CPU cores within the drive including the execution of arbitrary code, the modification of firmware execution flow and data or bypassing the firmware signature verification during boot-up.
Published:Dec 20, 2024
Last Modified:Jul 23, 2025
EPS:Dec 20, 2024
EPSS Score:0.00073
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Kioxia
Product
Cm6
Kioxia
Cm6
Vendor
Kioxia
Product
Cm6 Firmware
Kioxia
Cm6 Firmware
Vendor
Kioxia
Product
Pm6
Kioxia
Pm6
Vendor
Kioxia
Product
Pm6 Firmware
Kioxia
Pm6 Firmware
Vendor
Kioxia
Product
Pm7
Kioxia
Pm7
Vendor
Kioxia
Product
Pm7 Firmware
Kioxia
Pm7 Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
