4.7

CVE-2024-28970

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.

Data is provided by the National Vulnerability Database (NVD)
DellVostro 5502 Firmware Version < 1.30.0
   DellVostro 5502 Version-
DellVostro 5402 Firmware Version < 1.30.0
   DellVostro 5402 Version-
DellPrecision 3660 Firmware Version < 2.14.0
   DellPrecision 3660 Version-
DellInspiron 5509 Firmware Version < 1.30.0
   DellInspiron 5509 Version-
DellInspiron 5502 Firmware Version < 1.30.0
   DellInspiron 5502 Version-
DellInspiron 5409 Firmware Version < 1.30.0
   DellInspiron 5409 Version-
DellInspiron 5402 Firmware Version < 1.30.0
   DellInspiron 5402 Version-
DellInspiron 16 Plus 7640 Firmware Version < 1.6.0
   DellInspiron 16 Plus 7640 Version-
DellInspiron 16 7640 2-in-1 Firmware Version < 1.4.0
   DellInspiron 16 7640 2-in-1 Version-
DellInspiron 14 Plus 7440 Firmware Version < 1.6.0
   DellInspiron 14 Plus 7440 Version-
DellG7 7700 Firmware Version < 1.32.0
   DellG7 7700 Version-
DellG7 7500 Firmware Version < 1.32.0
   DellG7 7500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.126
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
security_alert@emc.com 4.7 0.5 4.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.