CVE-2022-24379: Input Validation
Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-24379?
CVE-2022-24379 is a vulnerability in some Intel Server System M70KLP Family BIOS firmware before version 01.04.0029 that may allow a privileged user to potentially enable escalation of privilege via local access.
How does CVE-2022-24379 affect Intel Server Board M70klp2sb Firmware?
Intel Server Board M70klp2sb Firmware versions up to 01.04.0022 are affected by CVE-2022-24379.
Is Intel Server Board M70klp2sb vulnerable to CVE-2022-24379?
No, Intel Server Board M70klp2sb is not vulnerable to CVE-2022-24379.
How does CVE-2022-24379 affect Intel Server System M70klp4s2uhh Firmware?
Intel Server System M70klp4s2uhh Firmware versions up to 01.04.0022 are affected by CVE-2022-24379.
Is Intel Server System M70klp4s2uhh vulnerable to CVE-2022-24379?
No, Intel Server System M70klp4s2uhh is not vulnerable to CVE-2022-24379.
What is the severity of CVE-2022-24379?
CVE-2022-24379 has a severity rating of 7.5 out of 10 (high).
How can I fix CVE-2022-24379?
To fix CVE-2022-24379, update your Intel Server System M70KLP Family BIOS firmware to version 01.04.0029 or later.
Where can I find more information about CVE-2022-24379?
You can find more information about CVE-2022-24379 on the Intel Security Center Advisory page at https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html.
What is the CWE category of CVE-2022-24379?
The CWE category of CVE-2022-24379 is CWE-20 (Improper Input Validation).