Input validation error in AMD Instinct MI300X - CVE-2024-21935

 

Input validation error in AMD Instinct MI300X - CVE-2024-21935

Published: February 24, 2025


Vulnerability identifier: #VU104142
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21935
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input in Satellite Management Controller (SMC). A remote attacker can pass specially crafted input to the application and remove files from the local root directory, resulting in data corruption.


Affected software

AMD Instinct MI300X
ThinkSystem SR685a V3
AMD Graphics Processing Unit (GPU) Adapter Firmware

How to mitigate CVE-2024-21935

Install updates from vendor's website.

AMD Instinct MI300X - update to 24.10
AMD Graphics Processing Unit (GPU) Adapter Firmware - update to BKC 24.12.10

External References

Related Security Bulletins