CVE-2024-21801

Aug. 14, 2024, 5:49 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Intel TDX module software

  • before 1.5.05.46.698

Source

secure@intel.com

Tags

CVE-2024-21801 details

Published : Aug. 14, 2024, 2:15 p.m.
Last Modified : Aug. 14, 2024, 5:49 p.m.

Description

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

CVSS Score

1 2 3 4 5 6 7.1 8 9 10

Weakness

Weakness Name Description
CWE-691 Insufficient Control Flow Management The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

7.1

Exploitability Score

2.5

Impact Score

4.0

Base Severity

HIGH

This website uses the NVD API, but is not approved or certified by it.