VYPR
Vendor

Nuvoton

Products
12
CVEs
5
Across products
12
Status
Private

Products

12

Recent CVEs

5
  • CVE-2019-14602HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-38433MedJul 11, 2024
    risk 0.44cvss 6.7epss 0.00

    Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to…

  • CVE-2021-32015MedJun 8, 2021
    risk 0.39cvss 6.0epss 0.00

    In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 will mitigate against the vulnerability, but version 7.4.0.1…

  • CVE-2020-25082LowAug 10, 2021
    risk 0.25cvss 3.8epss 0.00

    An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.

  • CVE-2026-10668LowJul 12, 2026
    risk 0.09cvss 2.4epss 0.00

    The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger). Because the HSUSBD hardware cannot disarm a control Data IN already armed for a previous…