CVE-2024-33659

HIGH

AMI APTIO V 5.0-5.038 - Improper Input Validation in BIOS

Title source: llm
STIX 2.1

Description

AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability.

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
ami/aptio_v 5.0 - 5.038
Published Feb 11, 2025
Tracked Since Feb 18, 2026