CVE-2024-29980: Unsafe Handling of IHV UEFI Variables
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Manipulation.This issue affects SecureCore™ for Intel Kaby Lake: before 4.0.1.1012; SecureCore™ for Intel Coffee Lake: before 4.1.0.568; SecureCore™ for Intel Comet Lake: before 4.2.1.292; SecureCore™ for Intel Ice Lake: before 4.2.0.334.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29980?
CVE-2024-29980 is classified as a high severity vulnerability due to its potential for input data manipulation.
Which versions of Phoenix SecureCore are affected by CVE-2024-29980?
CVE-2024-29980 affects Phoenix SecureCore for Intel Kaby Lake versions up to 4.0.1.1012, Coffee Lake versions up to 4.1.0.568, Comet Lake versions up to 4.2.1.292, and Ice Lake versions up to 4.2.0.334.
How do I fix CVE-2024-29980?
To fix CVE-2024-29980, users should update their Phoenix SecureCore software to the latest versions provided by Phoenix.
What type of vulnerability is CVE-2024-29980?
CVE-2024-29980 is categorized as an improper check for unusual or exceptional conditions vulnerability.
What are the potential risks of CVE-2024-29980?
The potential risks of CVE-2024-29980 include unauthorized input data manipulation that could lead to system compromise.