Improper Initialization in Intel products - CVE-2024-31157

 

Improper Initialization in Intel products - CVE-2024-31157

Published: February 18, 2025


Vulnerability identifier: #VU104040
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31157
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper initialization in OutOfBandXML module. A local user can gain unauthorized access to sensitive information on the system.


Affected software

UEFI firmware
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Precision 5860 Tower
Precision 7960 Tower
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
openEuler
Fedora
microcode_ctl
Dell Integrated System for Microsoft Azure Stack Hub 16G

How to mitigate CVE-2024-31157

Install updates from vendor's website.

microcode_ctl - addressed in versions 2.1-61.6.fc40, 2.1-67.1.fc41
Precision 5860 Tower - update to 2.6.1
Precision 7960 Tower - update to 2.6.1
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
microcode_ctl - update to 20250211-1

External References

Related Security Bulletins