Race condition in UEFI firmware - CVE-2024-23599

 

Race condition in UEFI firmware - CVE-2024-23599

Published: September 17, 2024


Vulnerability identifier: #VU97445
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23599
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition in Seamless Firmware Updates for some Intel reference platforms. A local user can exploit the race and perform a denial of service (DoS) attack.


Affected software

UEFI firmware
Precision 7920 Rack
Precision 7920 XL Rack
HPE SimpliVity 380 Gen10
HPE SimpliVity 380 Gen10 G
HPE SimpliVity 380 Gen10 H
HPE SimpliVity 190r Gen10 Server
HPE SimpliVity 170r Gen10 Server
HPE SimpliVity 380 Gen10 Plus
HPE SimpliVity 380 Gen11
APEX Cloud Platform for Microsoft Azure
F5OS
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2024-23599

Install updates from vendor's website.

APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
APEX Cloud Platform for Red Hat OpenShift - update to 03.03.00.00
HPE SimpliVity 380 Gen10 - update to 2024_1129
HPE SimpliVity 380 Gen10 G - update to 2024_1129
HPE SimpliVity 380 Gen10 H - update to 2024_1129
HPE SimpliVity 190r Gen10 Server - update to 2024_1129
HPE SimpliVity 170r Gen10 Server - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
HPE SimpliVity 380 Gen11 - update to 2024_1129

External References

Related Security Bulletins