CVE-2024-33660: Potential Firmware update without integrity check
Published Nov 12, 2024
·Updated
An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.
Affected Software
1 affected component
AMI Aptio V>=5.0<5.037
Event History
Nov 12, 2024
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33660?
The severity of CVE-2024-33660 is critical due to the potential for an attacker with physical access to manipulate SPI flash without detection.
2
How do I fix CVE-2024-33660?
To fix CVE-2024-33660, ensure that you upgrade to a version of AMI Aptio V above 5.037.
3
Who is affected by CVE-2024-33660?
CVE-2024-33660 affects systems using AMI Aptio V firmware versions from 5.0 to 5.037.
4
What type of vulnerability is CVE-2024-33660?
CVE-2024-33660 is a physical access vulnerability that allows for undetected manipulation of SPI flash.
5
Is physical access required to exploit CVE-2024-33660?
Yes, exploiting CVE-2024-33660 requires physical access to the vulnerable device.