Improper Check for Unusual or Exceptional Conditions in Intel Trust Domain Extensions (TDX) module - CVE-2024-27457

 

Improper Check for Unusual or Exceptional Conditions in Intel Trust Domain Extensions (TDX) module - CVE-2024-27457

Published: October 11, 2024


Vulnerability identifier: #VU98415
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27457
CWE-ID: CWE-754
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper check for unusual or exceptional conditions. A local administrator can send specially crafted data to the application and disclose sensitive information.


Affected software

Intel Trust Domain Extensions (TDX) module
ThinkAgile VX650 V3 DPU SAP HANA Certified Node
ThinkSystem ST658 V3
ThinkSystem ST650 V3
ThinkSystem SR950 V3
ThinkSystem SR860 V3
ThinkSystem SR850 V3
ThinkSystem SR650 V3
ThinkSystem SR630 V3
ThinkSystem SD650 V3
ThinkSystem SD550 V3
ThinkSystem SD530 V3
ThinkAgile VX650 V3 SAP HANA Certified Node
ThinkAgile VX650 V3 Integrated System
Lenovo WenTian WR5220 G3/WR5228 G3
ThinkAgile VX650 V3 DPU Integrated System
ThinkAgile VX650 V3 DPU Certified Node
ThinkAgile VX650 V3 Certified Node
ThinkAgile VX630 V3 Certified Node
ThinkAgile MX650 v3 Integrated System
ThinkAgile MX650 V3 Certified Node
ThinkAgile MX630 V3 Integrated System
ThinkAgile MX630 V3 Certified Node
ThinkAgile HX650 V3 Integrated System
ThinkAgile HX650 V3 Certified Node
ThinkAgile HX630 V3 Integrated System
ThinkAgile HX630 V3 Certified Node
Precision 7960 XL Rack
HPE Alletra 4140
HPE ProLiant DL110 Gen11
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE ProLiant DL560 Gen11
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE Alletra 4120
HPE Alletra 4110
Lenovo WR5220G3 UEFI Firmware (For AnyOS)
Lenovo System UEFI/BIOS Firmware
Dell Data Lakehouse
Precision 7960 Rack

How to mitigate CVE-2024-27457

Install updates from vendor's website.

Intel Trust Domain Extensions (TDX) module - update to 1.5.06
Lenovo WR5220G3 UEFI Firmware (For AnyOS) - update to T8E192K-2.80
Lenovo System UEFI/BIOS Firmware - update to USE132F
Dell Data Lakehouse - update to 1.4.0.0
Precision 7960 XL Rack - update to 2.4.4
Precision 7960 Rack - update to 2.4.4
HPE Alletra 4140 - update to 2.32_09-09-2024
HPE ProLiant DL110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant DL320 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380a Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL560 Gen11 - update to 2.32_09-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.32_09-09-2024
HPE Compute Edge Server e930t - update to 2.32_09-09-2024
HPE Alletra 4120 - update to 2.32_09-09-2024
HPE Alletra 4110 - update to 2.32_09-09-2024

External References

Related Security Bulletins