CVE-2024-21853 describes an improper finite state machine vulnerability in the hardware logic of some 4th and 5th Generation Intel Xeon Processors. An authorized local user could exploit this with high attack complexity to potentially cause a denial of service. The vulnerability has a CVSS score of 4.7 (Medium) and is not currently listed in CISA's KEV catalog. There is no public exploit code available, nor is there any significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | 4th And 5th Generation Intel(R) Xeon(R) Processors | See referencesCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.