#VU104136 Improper restriction of communication channel to intended endpoints in Intel products - CVE-2024-39271
Published: February 21, 2025
Vulnerability identifier: #VU104136
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-39271
CWE-ID: CWE-923
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Intel Wireless-AC 9260
Intel Killer Wi-Fi 1550x/w2
Intel Wireless-AC 9560
Intel Killer Wi-Fi 1550i/s2
Intel Wi-Fi 6 AX200
Intel Killer Wi-Fi 1650x/w2
Intel Wi-Fi 6E AX210
Intel Killer Wi-Fi 1675x/w2
Intel Wi-Fi 6E AX211
Intel Killer Wi-Fi 1675i/s2
Intel Wi-Fi 6 AX201
Intel Killer Wi-Fi 1650i/s2
Intel Wi-Fi 7 BE200
Intel Killer Wi-Fi 1750x/w2
Intel Wi-Fi 7 BE201
Intel Killer Wi-Fi r 1750i/s2
Intel Wi-Fi 7 BE202
Intel PROSet/Wireless WiFi Software for Windows
Intel Wireless-AC 9260
Intel Killer Wi-Fi 1550x/w2
Intel Wireless-AC 9560
Intel Killer Wi-Fi 1550i/s2
Intel Wi-Fi 6 AX200
Intel Killer Wi-Fi 1650x/w2
Intel Wi-Fi 6E AX210
Intel Killer Wi-Fi 1675x/w2
Intel Wi-Fi 6E AX211
Intel Killer Wi-Fi 1675i/s2
Intel Wi-Fi 6 AX201
Intel Killer Wi-Fi 1650i/s2
Intel Wi-Fi 7 BE200
Intel Killer Wi-Fi 1750x/w2
Intel Wi-Fi 7 BE201
Intel Killer Wi-Fi r 1750i/s2
Intel Wi-Fi 7 BE202
Intel PROSet/Wireless WiFi Software for Windows
Software vendor:
Intel
Intel
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper restriction of communication channel to intended endpoints. A remote attacker on the local network can gain access to sensitive information on the system.
Remediation
Install updates from vendor's website.