CVE-2024-2315

HIGH

AMI APTIO V 5.0-5.037 - Improper Access Control

Title source: llm
STIX 2.1

Description

APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.

Scores

CVSS v3 7.1
EPSS 0.0013
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
ami/aptio_v 5.0 - 5.037
Published Nov 12, 2024
Tracked Since Feb 18, 2026