CVE-2024-38414

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 125
CWE ID 126

Summary

CVE-2024-38414 is a recently identified information disclosure vulnerability. During the core initialization process, firmware images are being processed, leading to the exposure of sensitive information. This issue can potentially allow unauthorized users to gain insight into the system's internal workings, potentially resulting in serious security consequences. The exact impact of this vulnerability varies depending on the specific system and configuration, but it is crucial that affected organizations apply the necessary patches to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share