CVE-2024-23984
published 2024-09-16CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
PriorityP419medium5.3CVSS 3.1
AVLACHPRHUINSCCHINAN
EPSS
0.21%
11.2th percentile
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240910.1~deb12u1 (bookworm) | intel-microcode 3.20240910.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.5HIGH
vendor_ubuntu7.2HIGH
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-12-11·CVSS 7.2
CVE-2024-24968 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allo
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-09-25·CVSS 5.3
CVE-2024-24968 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024-23984)
It was discovered that some Intel(R) Processors did not properly implement
finite state machines (FSMs) in hardware logic. This may allow a local
privileged attacker to cause a denial of service (system crash).
(CVE-2024-24968)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2024-23984: intel-microcode - Observable discrepancy in RAPL interface for some Intel(R) Processors may allow ...
vendor_debian·2024·CVSS 6.8
CVE-2024-23984 [MEDIUM] CVE-2024-23984: intel-microcode - Observable discrepancy in RAPL interface for some Intel(R) Processors may allow ...
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240910.1~deb12u1)
bullseye: resolved (fixed in 3.20240910.1~deb11u1)
forky: resolved (fixed in 3.20240910.1)
sid: resolved (fixed in 3.20240910.1)
trixie: resolved (fixed in 3.20240910.1)
OSV
intel-microcode vulnerabilities
osv·2024-12-11·CVSS 8.5
CVE-2024-21820 [HIGH] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024
OSV
intel-microcode vulnerabilities
osv·2024-09-25·CVSS 6.8
CVE-2024-23984 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024-23984)
It was discovered that some Intel(R) Processors did not properly implement
finite state machines (FSMs) in hardware logic. This may allow a local
privileged attacker to cause a denial of service (system crash).
(CVE-2024-24968)
GHSA
GHSA-m5wh-wcvg-3f5f: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc
ghsa_unreviewed·2024-09-16
CVE-2024-23984 [MEDIUM] CWE-203 GHSA-m5wh-wcvg-3f5f: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
OSV
CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc
osv·2024-09-16·CVSS 6.8
CVE-2024-23984 [MEDIUM] CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via loc
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-16
Published