Input validation error in Intel products - CVE-2024-22390
Published: May 22, 2024
Vulnerability identifier: #VU89741
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22390
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Intel Agilex 7 FPGA and SoC FPGA
Intel Stratix 10 FPGA and SoC FPGA
Intel Field Programmable Gate Array (FPGA)
Intel Stratix 10 FPGA and SoC FPGA
Intel Field Programmable Gate Array (FPGA)
How to mitigate CVE-2024-22390
Install updates from vendor's website.
Intel Field Programmable Gate Array (FPGA) - update to 2.9.1