Skip to main content

Improper Write Handling in Limited-write Non-Volatile Memories

CVE-2024-36432

Severity High
Score 7.5/10

Summary

An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4.

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • NONE
  • HIGH
  • HIGH
  • HIGH

CWE-1246 - Improper Write Handling in Limited-write Non-Volatile Memories

The product does not implement or incorrectly implements wear leveling operations in limited-write non-volatile memories.

References

Advisory Timeline

  • Published