Time-of-check Time-of-use (TOCTOU) Race Condition in Intel products - CVE-2024-22185
Published: November 18, 2024
Vulnerability identifier: #VU100573
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22185
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local administrator can gain elevated privileges on the target system.
Affected software
Intel Alias Checking Trusted Module (ACTM)
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Precision 7960 XL Rack
HPE StoreEasy 1670 Storage
HPE StoreEasy 1870 Performance Storage
HPE StoreEasy 1870 Storage
HPE StoreEasy 1670 Performance Storage
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE ProLiant ML110 Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant ML350 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL110 Gen11
HPE Alletra 4140
HPE Alletra 4120
HPE Alletra 4110
HPE SimpliVity 380 Gen11
Precision 7960 Rack
HPE StoreEasy 1570 Performance
HPE StoreEasy 1570 Storage
HPE StoreEasy 1470 Performance
HPE StoreEasy 1470 Storage
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Precision 7960 XL Rack
HPE StoreEasy 1670 Storage
HPE StoreEasy 1870 Performance Storage
HPE StoreEasy 1870 Storage
HPE StoreEasy 1670 Performance Storage
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE ProLiant ML110 Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant ML350 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL110 Gen11
HPE Alletra 4140
HPE Alletra 4120
HPE Alletra 4110
HPE SimpliVity 380 Gen11
Precision 7960 Rack
HPE StoreEasy 1570 Performance
HPE StoreEasy 1570 Storage
HPE StoreEasy 1470 Performance
HPE StoreEasy 1470 Storage
How to mitigate CVE-2024-22185
Install updates from vendor's website.
Precision 7960 Rack - update to 2.4.4
Precision 7960 XL Rack - update to 2.4.4
HPE StoreEasy 1670 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1670 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1570 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1570 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1470 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1470 Storage - update to 2.30_08-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.30_08-09-2024
HPE Compute Edge Server e930t - update to 2.30_08-09-2024
HPE ProLiant ML110 Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL560 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380a Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL320 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL110 Gen11 - update to 2.30_08-09-2024
HPE Alletra 4140 - update to 2.30_08-09-2024
HPE Alletra 4120 - update to 2.30_08-09-2024
HPE Alletra 4110 - update to 2.30_08-09-2024
HPE SimpliVity 380 Gen11 - update to 2024_1129
Precision 7960 XL Rack - update to 2.4.4
HPE StoreEasy 1670 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1670 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1570 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1570 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1470 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1470 Storage - update to 2.30_08-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.30_08-09-2024
HPE Compute Edge Server e930t - update to 2.30_08-09-2024
HPE ProLiant ML110 Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL560 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380a Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL320 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL110 Gen11 - update to 2.30_08-09-2024
HPE Alletra 4140 - update to 2.30_08-09-2024
HPE Alletra 4120 - update to 2.30_08-09-2024
HPE Alletra 4110 - update to 2.30_08-09-2024
HPE SimpliVity 380 Gen11 - update to 2024_1129
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel ACTM Module Software
- HPE SimpliVity servers update for Intel ACTM module software
- Multiple vulnerabilities in Dell Precision Rack BIOS
- Multiple vulnerabilities in Certain HPE ProLiant DL/ML, Alletra, Synergy, and Edgeline servers Using Certain Intel Processors
- Multiple vulnerabilities in Certain HPE StoreEasy servers Using Certain Intel Processors