CVE-2024-24968
published 2024-09-16CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via…
PriorityP415medium5.3CVSS 3.1
AVLACHPRHUINSCCNINAH
EPSS
0.18%
8.3th percentile
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240910.1~deb12u1 (bookworm) | intel-microcode 3.20240910.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv4.05.6MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.5HIGH
cisa9.8CRITICAL
vendor_ubuntu7.2HIGH
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-12-11·CVSS 7.2
CVE-2024-24968 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allo
CISA
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
cisa·2024-11-20·CVSS 9.8
CVE-2024-38812 [CRITICAL] CWE-122 VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Vulnerability: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38812
Remediation Due Date: 2024-12-11
CISA
VMware vCenter Server Privilege Escalation Vulnerability
cisa·2024-11-20·CVSS 9.8
CVE-2024-38813 [HIGH] CWE-250 VMware vCenter Server Privilege Escalation Vulnerability
Vulnerability: VMware vCenter Server Privilege Escalation Vulnerability
Affected: VMware vCenter Server
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813
Remediation Due Date: 2024-12-11
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-09-25·CVSS 5.3
CVE-2024-24968 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024-23984)
It was discovered that some Intel(R) Processors did not properly implement
finite state machines (FSMs) in hardware logic. This may allow a local
privileged attacker to cause a denial of service (system crash).
(CVE-2024-24968)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
microcode_ctl: Denial of Service
vendor_redhat·2024-09-16·CVSS 5.6
CVE-2024-24968 [MEDIUM] CWE-1245 microcode_ctl: Denial of Service
microcode_ctl: Denial of Service
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
A flaw was found in intel Processors. Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to enable a denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Out of support scope
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Out of support scope
Package: microcode_ctl (Red Hat Enterprise Linux 8) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2024-24968: intel-microcode - Improper finite state machines (FSMs) in hardware logic in some Intel(R) Process...
vendor_debian·2024·CVSS 5.6
CVE-2024-24968 [MEDIUM] CVE-2024-24968: intel-microcode - Improper finite state machines (FSMs) in hardware logic in some Intel(R) Process...
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20240910.1~deb12u1)
bullseye: resolved (fixed in 3.20240910.1~deb11u1)
forky: resolved (fixed in 3.20240910.1)
sid: resolved (fixed in 3.20240910.1)
trixie: resolved (fixed in 3.20240910.1)
OSV
intel-microcode vulnerabilities
osv·2024-12-11·CVSS 8.5
CVE-2024-21820 [HIGH] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R)
Xeon(R) processors did not properly restrict access to the memory
controller when using Intel(R) SGX. This may allow a local privileged
attacker to further escalate their privileges. (CVE-2024-21820,
CVE-2024-23918)
It was discovered that some 4th and 5th Generation Intel(R) Xeon(R)
Processors did not properly implement finite state machines (FSMs) in
hardware logic. THis may allow a local privileged attacker to cause a
denial of service (system crash). (CVE-2024-21853)
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024
OSV
intel-microcode vulnerabilities
osv·2024-09-25·CVSS 6.8
CVE-2024-23984 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel(R) Processors did not properly restrict
access to the Running Average Power Limit (RAPL) interface. This may allow
a local privileged attacker to obtain sensitive information.
(CVE-2024-23984)
It was discovered that some Intel(R) Processors did not properly implement
finite state machines (FSMs) in hardware logic. This may allow a local
privileged attacker to cause a denial of service (system crash).
(CVE-2024-24968)
OSV
CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of ser
osv·2024-09-16·CVSS 5.6
CVE-2024-24968 [MEDIUM] CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of ser
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
GHSA
GHSA-r3xc-mh5x-gjfq: Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of ser
ghsa_unreviewed·2024-09-16
CVE-2024-24968 [MEDIUM] CWE-1245 GHSA-r3xc-mh5x-gjfq: Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of ser
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
No detection rules found.
No public exploits indexed.
2024-09-16
Published