CVE-2024-42642

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:crucial:mx500_firmware:m3cr046:*:*:*:*:*:*:*
OR cpe:2.3:h:crucial:ct1000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct2000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct250mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct4000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct500mx500ssd1:-:*:*:*:*:*:*:*

History

05 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-120

04 Feb 2026, 18:16

Type Values Removed Values Added
References
  • () https://www.crucial.com/support/ssd-support/mx500-support -
Summary (en) Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. (en) Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

24 Oct 2024, 17:35

Type Values Removed Values Added
CWE CWE-121

10 Sep 2024, 13:46

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:h:crucial:ct1000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:o:crucial:mx500_firmware:m3cr046:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct4000mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct250mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct500mx500ssd1:-:*:*:*:*:*:*:*
cpe:2.3:h:crucial:ct2000mx500ssd1:-:*:*:*:*:*:*:*
References () http://microncrucial.com - () http://microncrucial.com - Broken Link
References () https://github.com/VL4DR/CVE-2024-42642/tree/main - () https://github.com/VL4DR/CVE-2024-42642/tree/main - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.7
First Time Crucial ct500mx500ssd1
Crucial ct250mx500ssd1
Crucial ct4000mx500ssd1
Crucial ct2000mx500ssd1
Crucial ct1000mx500ssd1
Crucial
Crucial mx500 Firmware

05 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Sep 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Micron Crucial MX500 Series Solid State Drives M3CR046 son vulnerables al desbordamiento de búfer, que puede desencadenarse al enviar paquetes ATA especialmente manipulados desde el host al controlador de la unidad.

04 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-04 20:15

Updated : 2026-02-05 15:16


NVD link : CVE-2024-42642

Mitre link : CVE-2024-42642

CVE.ORG link : CVE-2024-42642


JSON object : View

Products Affected

crucial

  • ct1000mx500ssd1
  • ct500mx500ssd1
  • ct4000mx500ssd1
  • ct250mx500ssd1
  • mx500_firmware
  • ct2000mx500ssd1
CWE
CWE-787

Out-of-bounds Write

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')