Input validation error in Intel products - CVE-2024-38307
Published: February 19, 2025
Vulnerability identifier: #VU104063
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-38307
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
Converged Security and Management Engine (CSME)
Intel Active Management Technology
Intel C420 Chipset
Intel X299 Chipset
Intel C620 Series Chipset
8th Gen Intel Core processor
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel C230 series chipset
Intel C240 Series Chipset
Intel 300 Series Chipset
Pentium Gold processor series (G54XXU)
Celeron processor 4000 series
Standard Manageability (ISM)
Converged Security and Management Engine (CSME)
Intel Active Management Technology
Intel C420 Chipset
Intel X299 Chipset
Intel C620 Series Chipset
8th Gen Intel Core processor
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel C230 series chipset
Intel C240 Series Chipset
Intel 300 Series Chipset
Pentium Gold processor series (G54XXU)
Celeron processor 4000 series
Standard Manageability (ISM)
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
How to mitigate CVE-2024-38307
Install updates from vendor's website.