#VU104063 Input validation error in Intel products - CVE-2024-38307
Published: February 19, 2025
Vulnerability identifier: #VU104063
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-38307
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Converged Security and Management Engine (CSME)
Intel Active Management Technology
Intel C420 Chipset
Intel X299 Chipset
Intel C620 Series Chipset
8th Gen Intel Core processor
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel C230 series chipset
Intel C240 Series Chipset
Intel 300 Series Chipset
Pentium Gold processor series (G54XXU)
Celeron processor 4000 series
Standard Manageability (ISM)
Converged Security and Management Engine (CSME)
Intel Active Management Technology
Intel C420 Chipset
Intel X299 Chipset
Intel C620 Series Chipset
8th Gen Intel Core processor
Intel 100 Series Chipset
Intel 200 Series Chipset
Intel C230 series chipset
Intel C240 Series Chipset
Intel 300 Series Chipset
Pentium Gold processor series (G54XXU)
Celeron processor 4000 series
Standard Manageability (ISM)
Software vendor:
Intel
Intel
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.