Improper Check for Unusual or Exceptional Conditions in Intel Trust Domain Extensions (TDX) module - CVE-2024-27457
Published: October 11, 2024
Vulnerability identifier: #VU98415
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27457
CWE-ID: CWE-754
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to improper check for unusual or exceptional conditions. A local administrator can send specially crafted data to the application and disclose sensitive information.
Affected software
Intel Trust Domain Extensions (TDX) module
ThinkAgile VX650 V3 DPU SAP HANA Certified Node
ThinkSystem ST658 V3
ThinkSystem ST650 V3
ThinkSystem SR950 V3
ThinkSystem SR860 V3
ThinkSystem SR850 V3
ThinkSystem SR650 V3
ThinkSystem SR630 V3
ThinkSystem SD650 V3
ThinkSystem SD550 V3
ThinkSystem SD530 V3
ThinkAgile VX650 V3 SAP HANA Certified Node
ThinkAgile VX650 V3 Integrated System
Lenovo WenTian WR5220 G3/WR5228 G3
ThinkAgile VX650 V3 DPU Integrated System
ThinkAgile VX650 V3 DPU Certified Node
ThinkAgile VX650 V3 Certified Node
ThinkAgile VX630 V3 Certified Node
ThinkAgile MX650 v3 Integrated System
ThinkAgile MX650 V3 Certified Node
ThinkAgile MX630 V3 Integrated System
ThinkAgile MX630 V3 Certified Node
ThinkAgile HX650 V3 Integrated System
ThinkAgile HX650 V3 Certified Node
ThinkAgile HX630 V3 Integrated System
ThinkAgile HX630 V3 Certified Node
Precision 7960 XL Rack
HPE Alletra 4140
HPE ProLiant DL110 Gen11
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE ProLiant DL560 Gen11
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE Alletra 4120
HPE Alletra 4110
Lenovo WR5220G3 UEFI Firmware (For AnyOS)
Lenovo System UEFI/BIOS Firmware
Dell Data Lakehouse
Precision 7960 Rack
ThinkAgile VX650 V3 DPU SAP HANA Certified Node
ThinkSystem ST658 V3
ThinkSystem ST650 V3
ThinkSystem SR950 V3
ThinkSystem SR860 V3
ThinkSystem SR850 V3
ThinkSystem SR650 V3
ThinkSystem SR630 V3
ThinkSystem SD650 V3
ThinkSystem SD550 V3
ThinkSystem SD530 V3
ThinkAgile VX650 V3 SAP HANA Certified Node
ThinkAgile VX650 V3 Integrated System
Lenovo WenTian WR5220 G3/WR5228 G3
ThinkAgile VX650 V3 DPU Integrated System
ThinkAgile VX650 V3 DPU Certified Node
ThinkAgile VX650 V3 Certified Node
ThinkAgile VX630 V3 Certified Node
ThinkAgile MX650 v3 Integrated System
ThinkAgile MX650 V3 Certified Node
ThinkAgile MX630 V3 Integrated System
ThinkAgile MX630 V3 Certified Node
ThinkAgile HX650 V3 Integrated System
ThinkAgile HX650 V3 Certified Node
ThinkAgile HX630 V3 Integrated System
ThinkAgile HX630 V3 Certified Node
Precision 7960 XL Rack
HPE Alletra 4140
HPE ProLiant DL110 Gen11
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE ProLiant DL560 Gen11
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE Alletra 4120
HPE Alletra 4110
Lenovo WR5220G3 UEFI Firmware (For AnyOS)
Lenovo System UEFI/BIOS Firmware
Dell Data Lakehouse
Precision 7960 Rack
How to mitigate CVE-2024-27457
Install updates from vendor's website.
Intel Trust Domain Extensions (TDX) module - update to 1.5.06
Lenovo WR5220G3 UEFI Firmware (For AnyOS) - update to T8E192K-2.80
Lenovo System UEFI/BIOS Firmware - update to USE132F
Dell Data Lakehouse - update to 1.4.0.0
Precision 7960 XL Rack - update to 2.4.4
Precision 7960 Rack - update to 2.4.4
HPE Alletra 4140 - update to 2.32_09-09-2024
HPE ProLiant DL110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant DL320 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380a Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL560 Gen11 - update to 2.32_09-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.32_09-09-2024
HPE Compute Edge Server e930t - update to 2.32_09-09-2024
HPE Alletra 4120 - update to 2.32_09-09-2024
HPE Alletra 4110 - update to 2.32_09-09-2024
Lenovo WR5220G3 UEFI Firmware (For AnyOS) - update to T8E192K-2.80
Lenovo System UEFI/BIOS Firmware - update to USE132F
Dell Data Lakehouse - update to 1.4.0.0
Precision 7960 XL Rack - update to 2.4.4
Precision 7960 Rack - update to 2.4.4
HPE Alletra 4140 - update to 2.32_09-09-2024
HPE ProLiant DL110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant DL320 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL380a Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML110 Gen11 - update to 2.32_09-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.32_09-09-2024
HPE ProLiant DL560 Gen11 - update to 2.32_09-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.32_09-09-2024
HPE Compute Edge Server e930t - update to 2.32_09-09-2024
HPE Alletra 4120 - update to 2.32_09-09-2024
HPE Alletra 4110 - update to 2.32_09-09-2024
External References
Related Security Bulletins
- Information disclosure in Intel TDX Module
- Multiple vulnerabilities in Dell Precision Rack BIOS for Intel Xeon Processor and Intel TDX Module
- Improper check for unusual or exceptional conditions in Certain HPE ProLiant DL/ML, Synergy, Alletra, and Edgeline Servers Using Certain Intel Processors
- Dell Data Lakehouse update for third-party components
- Lenovo update for Intel TDX Module Software