Input validation error in Intel Xeon D Processors and 3rd Generation Intel Xeon Scalable Processors - CVE-2024-21829
Published: September 17, 2024
Vulnerability identifier: #VU97437
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21829
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in UEFI firmware error handler. A local privileged user can execute arbitrary code with elevated privileges.
Affected software
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
Precision 7920 Rack
Precision 7920 XL Rack
Superdome Flex Server
HPE SimpliVity 380 Gen10
HPE SimpliVity 380 Gen10 G
HPE SimpliVity 380 Gen10 H
HPE SimpliVity 190r Gen10 Server
HPE SimpliVity 170r Gen10 Server
HPE SimpliVity 380 Gen10 Plus
HPE SimpliVity 380 Gen11
APEX Cloud Platform for Microsoft Azure
F5OS
APEX Cloud Platform for Red Hat OpenShift
3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
Precision 7920 Rack
Precision 7920 XL Rack
Superdome Flex Server
HPE SimpliVity 380 Gen10
HPE SimpliVity 380 Gen10 G
HPE SimpliVity 380 Gen10 H
HPE SimpliVity 190r Gen10 Server
HPE SimpliVity 170r Gen10 Server
HPE SimpliVity 380 Gen10 Plus
HPE SimpliVity 380 Gen11
APEX Cloud Platform for Microsoft Azure
F5OS
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2024-21829
Install updates from vendor's website.
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Superdome Flex 280 Server - update to 1.90.12
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
APEX Cloud Platform for Red Hat OpenShift - update to 03.03.00.00
Superdome Flex Server - update to 4.0.10
HPE SimpliVity 380 Gen10 - update to 2024_1129
HPE SimpliVity 380 Gen10 G - update to 2024_1129
HPE SimpliVity 380 Gen10 H - update to 2024_1129
HPE SimpliVity 190r Gen10 Server - update to 2024_1129
HPE SimpliVity 170r Gen10 Server - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
HPE SimpliVity 380 Gen11 - update to 2024_1129
Superdome Flex 280 Server - update to 1.90.12
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
APEX Cloud Platform for Red Hat OpenShift - update to 03.03.00.00
Superdome Flex Server - update to 4.0.10
HPE SimpliVity 380 Gen10 - update to 2024_1129
HPE SimpliVity 380 Gen10 G - update to 2024_1129
HPE SimpliVity 380 Gen10 H - update to 2024_1129
HPE SimpliVity 190r Gen10 Server - update to 2024_1129
HPE SimpliVity 170r Gen10 Server - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
HPE SimpliVity 380 Gen11 - update to 2024_1129
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel UEFI firmware
- HPE Superdome Flex and Superdome Flex 280 servers update for Intel UEFI firmware
- Privilege escalation in F5OS Intel UEFI firmware
- Dell Precision Rack update for Intel CPU firmware
- HPE SimpliVity servers update for Intel UEFI firmware
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- APEX Cloud Platform for Microsoft Azure update for third-party components