APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.
History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Tue, 12 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Description APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.
Title SMM arbitrary code execution in Overclock
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMI

Published: 2024-11-12T15:01:15.370Z

Updated: 2024-11-21T16:20:52.843Z

Reserved: 2024-03-08T04:05:51.850Z

Link: CVE-2024-2315

cve-icon Vulnrichment

Updated: 2024-11-12T15:54:57.728Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T15:15:07.737

Modified: 2024-11-21T17:15:12.817

Link: CVE-2024-2315

cve-icon Redhat

No data.