PT-2024-19122 · Amd · Amd Cloud Manageability Service

Published

2024-11-12

·

Updated

2024-12-18

·

CVE-2024-21939

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AMD Cloud Manageability Service (ACMS) Software (affected versions not specified)
Description The issue is related to incorrect default permissions in the installation directory of the AMD Cloud Manageability Service (ACMS) Software. This could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-21939

Affected Products

Amd Cloud Manageability Service