CVE-2024-31153
Last modified
CVE-2024-31153 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Quickassist Technology | < 2.2.0-0012 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-31153?
How severe is CVE-2024-31153?
How do I fix CVE-2024-31153?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-31145Certain PCI devices in a system might be assigned Reserved M…7.5
- CVE-2024-31146When multiple devices share resources and one of them is to …7.5
- CVE-2024-3115An issue was discovered in GitLab EE affecting all versions …4.3
- CVE-2024-31150Out-of-bounds read for some Intel(R) Graphics Driver softwar…4.8
- CVE-2024-31151A security flaw involving hard-coded credentials in LevelOne…9.8
- CVE-2024-31152The LevelOne WBR-6012 router with firmware R0.40e6 is vulner…7.5
- CVE-2024-31154Improper input validation in UEFI firmware for some Intel(R)…8.7
- CVE-2024-31155Improper buffer restrictions in the UEFI firmware for some I…8.7
- CVE-2024-31156 A stored cross-site scripting (XSS) vulnerability exists in…8
- CVE-2024-31157Improper initialization in UEFI firmware OutOfBandXML module…6.8
- CVE-2024-31158Improper input validation in UEFI firmware in some Intel(R) …8.7
- CVE-2024-31159The parameter used in the certain page of ASUS Download Mast…4.8
Are you affected by CVE-2024-31153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
