Skip to main content

Hardware Logic with Insecure De-Synchronization between Control and Data Channels

CVE-2024-21823

Severity High
Score 7.5/10

Summary

Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable escalation of privilege local access

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • NONE
  • LOW
  • NONE
  • HIGH

CWE-1264 - Hardware Logic with Insecure De-Synchronization between Control and Data Channels

The hardware logic for error handling and security checks can incorrectly forward data before the security check is complete.

References

Advisory Timeline

  • Published