CVE-2024-21829: Input Validation
Published Sep 16, 2024
·Updated
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
2 affected componentsFixes available
F5 F5OS-A>=1.7.0<=1.8.0, >=1.5.1<=1.5.3
F5 F5OS-C=1.8.0, >=1.6.0<=1.6.2
1.8.1
Event History
Sep 16, 2024
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Oct 18, 2024
Advisory Published
via F5·08:50 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-21829?
CVE-2024-21829 has a high severity rating due to the potential escalation of privilege that it enables for privileged users.
2
How do I fix CVE-2024-21829?
To fix CVE-2024-21829, update the affected F5OS-A or F5OS-C to the latest version provided by F5.
3
Who is affected by CVE-2024-21829?
CVE-2024-21829 affects users running specific versions of F5OS-A and F5OS-C on Intel processors.
4
What type of vulnerability is CVE-2024-21829?
CVE-2024-21829 is classified as an improper input validation vulnerability in UEFI firmware error handling.
5
Can CVE-2024-21829 be exploited remotely?
CVE-2024-21829 requires local access, meaning it cannot be exploited remotely without physical access to the device.