Improper Handling of Unexpected Data Type
CVE-2024-21935
Summary
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.
- LOW
- NETWORK
- LOW
- CHANGED
- NONE
- LOW
- NONE
- NONE
CWE-241 - Improper Handling of Unexpected Data Type
The software does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).
References
Advisory Timeline
- Published