CVE-2024-21853
published 2024-11-13CVE-2024-21853: Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to…
PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.20%
10.4th percentile
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20241112.1~deb12u1 (bookworm) | intel-microcode 3.20241112.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.05.7MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.5HIGH
vendor_ubuntu7.2HIGH
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-12-11·CVSS 7.2
CVE-2024-24968 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allo
Red Hat
kernel: microcode_ctl: From CVEorg collector
vendor_redhat·2024-11-13·CVSS 5.7
CVE-2024-21853 [MEDIUM] CWE-1245 kernel: microcode_ctl: From CVEorg collector
kernel: microcode_ctl: From CVEorg collector
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 8) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2024-21853: intel-microcode - Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th ...
vendor_debian·2024·CVSS 5.7
CVE-2024-21853 [MEDIUM] CVE-2024-21853: intel-microcode - Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th ...
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20241112.1~deb12u1)
bullseye: resolved (fixed in 3.20241112.1~deb11u1)
forky: resolved (fixed in 3.20241112.1)
sid: resolved (fixed in 3.20241112.1)
trixie: resolved (fixed in 3.20241112.1)
OSV
intel-microcode vulnerabilities
osv·2024-12-11·CVSS 8.5
CVE-2024-21820 [HIGH] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024
OSV
CVE-2024-21853: Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to
osv·2024-11-13·CVSS 5.7
CVE-2024-21853 [MEDIUM] CVE-2024-21853: Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.
GHSA
GHSA-f58g-ghv3-pqv3: Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to
ghsa_unreviewed·2024-11-13
CVE-2024-21853 [MEDIUM] CWE-1245 GHSA-f58g-ghv3-pqv3: Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to
Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-13
Published