CVE-2024-42642
Last modified
CVE-2024-42642 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Crucial | Mx500 Firmware | m3cr046 |
References
- https://github.com/VL4DR/CVE-2024-42642/tree/mainExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-42642?
How severe is CVE-2024-42642?
How do I fix CVE-2024-42642?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42636DedeCMS V5.7.115 has a command execution vulnerability via f…7.2
- CVE-2024-42637H3C R3010 v100R002L02 was discovered to contain a hardcoded …9.8
- CVE-2024-42638H3C Magic B1ST v100R012 was discovered to contain a hardcode…9.8
- CVE-2024-42639H3C GR1100-P v100R009 was discovered to use a hardcoded pass…9.8
- CVE-2024-4264A remote code execution (RCE) vulnerability exists in the be…9.8
- CVE-2024-42640angular-base64-upload prior to v0.1.21 is vulnerable to unau…9.8
- CVE-2024-42643Integer Overflow in fast_ping.c in SmartDNS Release46 allows…7.5
- CVE-2024-42644FlashMQ v1.14.0 was discovered to contain an assertion failu…7.5
- CVE-2024-42645An issue in FlashMQ v1.14.0 allows attackers to cause an ass…7.5
- CVE-2024-42646A segmentation fault in NanoMQ v0.21.10 allows attackers to …7.5
- CVE-2024-42648NanoMQ v0.22.10 was discovered to contain a heap overflow wh…6.5
- CVE-2024-42649NanoMQ v0.22.10 was discovered to contain a memory leak whic…6.5
Are you affected by CVE-2024-42642?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
