CVE-2024-28047 Details
Description
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
A vulnerability exists in the UEFI firmware of certain Intel processors, allowing a privileged user to potentially disclose information through local access. This issue arises from improper input validation in the firmware.
Users are advised to update to the latest version provided by their system manufacturer that addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2025CISA-ADP
Assessed Feb 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/03/msg00021.html | CVE | |
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel Xeon Processor D | All versions |
CPE
Remediation
| |
| Intel Xeon Scalable Processor | All versions |
CPE
Remediation
| |
| Intel Pentium Processor Silver | All versions |
CPE
Remediation
| |
| Intel Celeron Processor J | All versions |
CPE
Remediation
| |
| Intel Celeron Processor N | All versions |
CPE
Remediation
| |
| Intel Core | All versions |
CPE
Remediation
| |
| Intel Pentium Gold | All versions |
CPE
Remediation
| |
| Intel Celeron | All versions |
CPE
Remediation
| |
| Intel Atom C5000 | All versions |
CPE
Remediation
| |
| Intel Atom P5000 | All versions |
CPE
Remediation
| |
| Intel Xeon W | All versions |
CPE
Remediation
| |
| Intel Atom X | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | CVE Modified | CISA-ADP |
| Feb 12, 2025 | New CVE Received | [email protected] |
Volerion