CVE-2024-21781: Input Validation
Published Sep 16, 2024
·Updated
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.
Affected Software
2 affected componentsFixes available
F5 F5OS-A>=1.7.0<=1.8.3, >=1.5.1<=1.5.4
1.8.4
F5 F5OS-C=1.8.0, >=1.6.0<=1.6.4
1.8.1
Event History
Sep 16, 2024
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Oct 19, 2024
Advisory Published
via F5·05:32 AM
Data Sourced
via F5·05:32 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21781?
CVE-2024-21781 is classified as a high severity vulnerability due to the potential for information disclosure and denial of service.
2
How do I fix CVE-2024-21781?
To fix CVE-2024-21781, upgrade to the latest available firmware versions provided by F5 for F5OS-A and F5OS-C.
3
Who is affected by CVE-2024-21781?
CVE-2024-21781 affects users of specific versions of F5OS-A and F5OS-C running on certain Intel processors.
4
What type of vulnerabilities are associated with CVE-2024-21781?
CVE-2024-21781 is associated with improper input validation vulnerabilities that can lead to local information disclosure or denial of service.
5
Is local access required to exploit CVE-2024-21781?
Yes, exploiting CVE-2024-21781 requires local access to the affected system.