CVE-2024-39285: Medium severity intel uefi firmware vulnerability
Published Nov 13, 2024
·Updated
Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
1 affected component
Intel Uefi Firmware
Event History
Nov 13, 2024
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39285?
CVE-2024-39285 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2024-39285?
To fix CVE-2024-39285, update the UEFI firmware to the latest version provided by Intel.
3
What causes CVE-2024-39285?
CVE-2024-39285 is caused by improper access control in the UEFI firmware of some Intel Server M20NTP Family systems.
4
What are the potential impacts of CVE-2024-39285?
The potential impact of CVE-2024-39285 is unauthorized information disclosure to a privileged user via local access.
5
Who is affected by CVE-2024-39285?
CVE-2024-39285 affects users of the Intel UEFI firmware on certain Intel Server M20NTP Family systems.