Observable discrepancy in Intel products - CVE-2024-23984

 

Observable discrepancy in Intel products - CVE-2024-23984

Published: September 17, 2024


Vulnerability identifier: #VU97424
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-23984
CWE-ID: CWE-203
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Intel Processor Microcode Package for Linux
Superdome Flex 280 Server
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
Precision 7920 Rack
Precision 7920 XL Rack
HPE SimpliVity 380 Gen11
HPE SimpliVity 380 Gen10 Plus
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
APEX Cloud Platform for Microsoft Azure
StoreEasy 1670 Expanded Storage
StoreEasy 1860 Expanded Storage
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
APEX Cloud Platform for Red Hat OpenShift
Apstra

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to observable discrepancy in Running Average Power Limit (RAPL) interface. A local privileged user can gain access to potentially sensitive information.


How to mitigate CVE-2024-23984

Install updates from vendor's website.

Sources