CVE-2024-28049: Input Validation
Published Nov 13, 2024
·Updated
Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access.
Affected Software
16 affected components
Intel PROSet/Wireless Software<23.40
Intel Killer Wi-Fi<23.40
All of the following
Any of the following
Intel Killer<23.40.0
Intel Proset\/wireless Wifi<23.40.0
Any of the following
Intel Killer Wi-fi 6 Ax1650
Intel Killer Wi-fi 6e Ax1675
Intel Killer Wi-fi 6e Ax1690
Intel Killer Wi-fi 7 Be1750
Intel Wi-fi 6 Ax200
Intel Wi-fi 6 Ax201
Intel Wi-fi 6e Ax210
Intel Wi-fi 6e Ax211
Intel Wi-fi 6e Ax411
Intel Wi-fi 7 Be200
Intel Wireless-ac 9260
Intel Wireless-ac 9560
Event History
Nov 13, 2024
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28049?
CVE-2024-28049 has a medium severity rating due to the potential for denial of service.
2
How do I fix CVE-2024-28049?
To mitigate CVE-2024-28049, update the Intel PROSet/Wireless Software or Intel Killer Wi-Fi to version 23.40 or later.
3
Which products are affected by CVE-2024-28049?
CVE-2024-28049 affects Intel PROSet/Wireless Software and Intel Killer Wi-Fi products prior to version 23.40.
4
What type of vulnerability is CVE-2024-28049?
CVE-2024-28049 is an improper input validation vulnerability that can lead to denial of service.
5
Who can exploit CVE-2024-28049?
An unauthenticated user within adjacent access can exploit CVE-2024-28049 to cause a denial of service.