Insufficient Control Flow Management in Intel Trust Domain Extensions (TDX) module - CVE-2024-21801
Published: August 16, 2024
Vulnerability identifier: #VU96067
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21801
CWE-ID: CWE-691
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient control flow management. A local attacker can perform a denial of service (DoS) attack.
Affected software
Intel Trust Domain Extensions (TDX) module
Precision 7960 XL Rack
Precision 7960 Rack
Precision 7960 XL Rack
Precision 7960 Rack
How to mitigate CVE-2024-21801
Install updates from vendor's website.
Intel Trust Domain Extensions (TDX) module - update to 1.5.05.46.698
Precision 7960 Rack - update to 2.2.7
Precision 7960 XL Rack - update to 2.2.7
Precision 7960 Rack - update to 2.2.7
Precision 7960 XL Rack - update to 2.2.7