PT-2025-36385 · Agesa · Agesa

Published

2025-09-06

·

Updated

2025-09-06

·

CVE-2024-21970

CVSS v3.1
4.4
VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Name of the Vulnerable Software and Affected Versions:

AND power Management Firmware (affected versions not specified)

Description:

Improper validation of an array index within the firmware could allow a privileged attacker to corrupt AGESA memory, potentially leading to a loss of system integrity.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2024-21970

Affected Products

Agesa