Skip to main content

Improper Handling of Unexpected Data Type

CVE-2024-21935

Severity Medium
Score 5/10

Summary

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-241 - Improper Handling of Unexpected Data Type

The software does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).

References

Advisory Timeline

  • Published