CVE-2024-31157: Medium severity intel uefi firmware vulnerability
Published Feb 12, 2025
·Updated
Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
1 affected component
Intel Uefi Firmware
Event History
Feb 12, 2025
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
May 25, 57089
Event
via NVD·10:03 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-31157?
CVE-2024-31157 has a moderate severity level due to the potential for information disclosure.
2
How do I fix CVE-2024-31157?
To fix CVE-2024-31157, update the UEFI firmware from Intel with the latest security patches.
3
Who is affected by CVE-2024-31157?
CVE-2024-31157 affects systems utilizing certain Intel UEFI firmware versions that include the OutOfBandXML module.
4
What type of vulnerability is CVE-2024-31157?
CVE-2024-31157 is an improper initialization vulnerability that could allow information disclosure.
5
Is there a workaround for CVE-2024-31157?
Currently, there is no known workaround for CVE-2024-31157 other than applying the firmware update.