CVE-2024-23984Observable Discrepancy in Intel-microcode

Severity
6.8MEDIUMNVD
OSV8.5
EPSS
0.0%
top 88.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateDec 11

Description

Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20240910.1~deb12u1 (bookworm)

🔴Vulnerability Details

4
OSV
intel-microcode vulnerabilities2024-12-11
OSV
intel-microcode vulnerabilities2024-09-25
GHSA
GHSA-m5wh-wcvg-3f5f: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc2024-09-16
OSV
CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc2024-09-16

📋Vendor Advisories

3
Ubuntu
Intel Microcode vulnerabilities2024-12-11
Ubuntu
Intel Microcode vulnerabilities2024-09-25
Debian
CVE-2024-23984: intel-microcode - Observable discrepancy in RAPL interface for some Intel(R) Processors may allow ...2024