CVE-2024-42642

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:crucial:mx500_firmware:m3cr046:*:*:*:*:*:*:*
OR cpe:2.3:h:crucial:ct1000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct2000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct250mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct4000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct500mx500ssd1:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-04 20:15

Updated : 2026-02-05 15:16


NVD link : CVE-2024-42642

Mitre link : CVE-2024-42642

CVE.ORG link : CVE-2024-42642


JSON object : View

Products Affected

crucial

  • ct250mx500ssd1
  • ct500mx500ssd1
  • ct1000mx500ssd1
  • ct2000mx500ssd1
  • mx500_firmware
  • ct4000mx500ssd1
CWE
CWE-787

Out-of-bounds Write

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')