CVE-2024-42642

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller.
References
Link Resource
http://microncrucial.com Broken Link
https://github.com/VL4DR/CVE-2024-42642/tree/main Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:crucial:mx500_firmware:m3cr046:*:*:*:*:*:*:*
OR cpe:2.3:h:crucial:ct1000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct2000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct250mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct4000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct500mx500ssd1:-:*:*:*:*:*:*:*

History

24 Oct 2024, 17:35

Type Values Removed Values Added
CWE CWE-121

10 Sep 2024, 13:46

Type Values Removed Values Added
CPE cpe:2.3:h:crucial:ct250mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:o:crucial:mx500_firmware:m3cr046:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct2000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct4000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct500mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct1000mx500ssd1:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.7
CWE CWE-787
First Time Crucial ct2000mx500ssd1
Crucial ct500mx500ssd1
Crucial mx500 Firmware
Crucial ct1000mx500ssd1
Crucial ct250mx500ssd1
Crucial
Crucial ct4000mx500ssd1
References () http://microncrucial.com - () http://microncrucial.com - Broken Link
References () https://github.com/VL4DR/CVE-2024-42642/tree/main - () https://github.com/VL4DR/CVE-2024-42642/tree/main - Exploit, Third Party Advisory

05 Sep 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-121

05 Sep 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Micron Crucial MX500 Series Solid State Drives M3CR046 son vulnerables al desbordamiento de búfer, que puede desencadenarse al enviar paquetes ATA especialmente manipulados desde el host al controlador de la unidad.

04 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-04 20:15

Updated : 2024-10-24 17:35


NVD link : CVE-2024-42642

Mitre link : CVE-2024-42642

CVE.ORG link : CVE-2024-42642


JSON object : View

Products Affected

crucial

  • mx500_firmware
  • ct2000mx500ssd1
  • ct1000mx500ssd1
  • ct500mx500ssd1
  • ct250mx500ssd1
  • ct4000mx500ssd1
CWE
CWE-787

Out-of-bounds Write