CVE Feed

    Dashboard / CVE / CVE-2024-42642

    CVE-2024-42642

    Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

    Published:Sep 4, 2024
    Last Modified:Feb 5, 2026
    EPS:Sep 4, 2024
    EPSS Score:0.04806
    CVSS Score:6.7

    Affected Products

    Vendor
    Crucial
    Product
    Ct1000mx500ssd1
    Vendor
    Crucial
    Product
    Ct2000mx500ssd1
    Vendor
    Crucial
    Product
    Ct250mx500ssd1
    Vendor
    Crucial
    Product
    Ct4000mx500ssd1
    Vendor
    Crucial
    Product
    Ct500mx500ssd1
    Vendor
    Crucial
    Product
    Mx500 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High