« Back to list

CVE-2024-22095

Status: DeferredHigh (7.2)—

Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-22095",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-22095",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-22T15:59:37.352402Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@intel.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 0.6
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "UEFI firmware for some Intel(R) Server D50DNP Family products",
          "versions": [
            {
              "status": "affected",
              "version": "See references"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:intel:server_system_d50tnp1mhcpac_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:intel:server_system_d50tnp1mhcrac_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:intel:server_system_d50tnp1mhcrlc_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:intel:server_system_d50tnp2mfalac_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:intel:server_system_d50tnp2mhstac_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:intel:server_system_d50tnp2mhsvac_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "intel",
          "product": "server_system_d50tnp2mhsvac_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-16T21:16:06.320",
  "references": [
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html",
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@intel.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access."
    },
    {
      "lang": "es",
      "value": " La validación de entrada incorrecta en el controlador PlatformVariableInitDxe en el firmware UEFI para algunos productos de la familia Intel(R) Server D50DNP puede permitir que un usuario privilegiado habilite la escalada de privilegios a través del acceso local."
    }
  ],
  "lastModified": "2026-06-17T07:10:42.220",
  "sourceIdentifier": "secure@intel.com"
}