Input validation error in C740 series chipset and Intel Server Platform Services Firmware - CVE-2024-25571

 

Input validation error in C740 series chipset and Intel Server Platform Services Firmware - CVE-2024-25571

Published: February 14, 2025


Vulnerability identifier: #VU103984
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25571
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

C740 series chipset
PowerEdge R760xa
Dell XC Core XC760xa
Dell XC Core XC660xs
Dell XC Core XC760
Dell XC Core XC660
PowerEdge XE9640
PowerEdge XE8640
PowerEdge XR7620
PowerEdge XR8620t
PowerEdge XR8610t
PowerEdge XR5610
PowerEdge XE9680
PowerEdge R660
PowerEdge T560
PowerEdge R760xd2
PowerEdge R760xs
PowerEdge R660xs
PowerEdge HS5620
PowerEdge HS5610
PowerEdge R960
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
Intel Server Platform Services Firmware
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G

How to mitigate CVE-2024-25571

Install updates from vendor's website.

Intel Server Platform Services Firmware - update to SPS_E5_06.01.04.059.0
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502

External References

Related Security Bulletins