8.2

CVE-2024-32858

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellXps 8960 Firmware Version < 2.6.0
   DellXps 8960 Version-
DellXps 8950 Firmware Version < 1.19.0
   DellXps 8950 Version-
DellInspiron 3502 Firmware Version < 1.16.0
   DellInspiron 3502 Version-
DellInspiron 15 3521 Firmware Version < 1.14.0
   DellInspiron 15 3521 Version-
DellInspiron 15 3510 Firmware Version < 1.19.0
   DellInspiron 15 3510 Version-
DellAurora R16 Firmware Version < 2.7.0
   DellAurora R16 Version-
DellAlienware X17 R2 Firmware Version < 1.20.0
   DellAlienware X17 R2 Version-
DellAlienware X17 R1 Firmware Version < 1.22.0
   DellAlienware X17 R1 Version-
DellAlienware X15 R2 Firmware Version < 1.20.0
   DellAlienware X15 R2 Version-
DellAlienware X15 R1 Firmware Version < 1.22.0
   DellAlienware X15 R1 Version-
DellAlienware X14 Firmware Version < 1.18.0
   DellAlienware X14 Version-
DellAlienware M17 R4 Firmware Version < 1.21.0
   DellAlienware M17 R4 Version-
DellAlienware M17 R3 Firmware Version < 1.27.0
   DellAlienware M17 R3 Version-
DellAlienware M15 R4 Firmware Version < 1.21.0
   DellAlienware M15 R4 Version-
DellAlienware M15 R3 Firmware Version < 1.27.0
   DellAlienware M15 R3 Version-
DellAlienware Aurora R15 Amd Firmware Version < 1.13.0
   DellAlienware Aurora R15 Amd Version-
DellAlienware Aurora R15 Firmware Version < 1.12.0
   DellAlienware Aurora R15 Version-
DellAlienware Aurora R13 Firmware Version < 1.19.0
   DellAlienware Aurora R13 Version-
DellAlienware Aurora R12 Firmware Version < 1.1.25
   DellAlienware Aurora R12 Version-
DellAlienware Aurora R11 Firmware Version < 1.0.24
   DellAlienware Aurora R11 Version-
DellAlienware Aurora R10 Firmware Version < 2.8.0
   DellAlienware Aurora R10 Version-
DellAlienware Area 51m R2 Firmware Version < 1.26.0
   DellAlienware Area 51m R2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
security_alert@emc.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.