6.8

CVE-2024-0160

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellXps 17 9700 Firmware Version < 1.30.0
   DellXps 17 9700 Version-
DellXps 15 9500 Firmware Version < 1.31.0
   DellXps 15 9500 Version-
DellVostro 7500 Firmware Version < 1.28.0
   DellVostro 7500 Version-
DellPrecision 5750 Firmware Version < 1.30.0
   DellPrecision 5750 Version-
DellPrecision 5550 Firmware Version < 1.31.0
   DellPrecision 5550 Version-
DellLatitude 3520 Firmware Version < 1.36.0
   DellLatitude 3520 Version-
DellLatitude 3510 Firmware Version < 1.29.0
   DellLatitude 3510 Version-
DellLatitude 3420 Firmware Version < 1.36.0
   DellLatitude 3420 Version-
DellLatitude 3410 Firmware Version < 1.29.0
   DellLatitude 3410 Version-
DellInspiron 7501 Firmware Version < 1.28.0
   DellInspiron 7501 Version-
DellInspiron 7500 Firmware Version < 1.28.0
   DellInspiron 7500 Version-
DellG7 7700 Firmware Version < 1.32.0
   DellG7 7700 Version-
DellG7 7500 Firmware Version < 1.32.0
   DellG7 7500 Version-
DellG5 5500 Firmware Version < 1.30.0
   DellG5 5500 Version-
DellG3 3500 Firmware Version < 1.30.0
   DellG3 3500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security_alert@emc.com 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.