6.5
CVE-2024-38304
- EPSS 0.1%
- Published 29.08.2024 11:15:26
- Last modified 20.12.2024 14:41:01
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Emc Xc Core Xcxr2 Firmware Version < 2.22.1
Dell ≫ Emc Xc Core Xc940 System Firmware Version < 2.22.2
Dell ≫ Emc Xc Core Xc740xd2 Firmware Version < 2.22.1
Dell ≫ Emc Xc Core Xc740xd System Firmware Version < 2.22.2
Dell ≫ Emc Xc Core Xc640 System Firmware Version < 2.22.2
Dell ≫ Emc Xc Core 6420 System Firmware Version < 2.22.2
Dell ≫ Emc Storage Nx3340 Firmware Version < 2.22.2
Dell ≫ Emc Storage Nx3240 Firmware Version < 2.22.2
Dell ≫ Poweredge Xe7440 Firmware Version < 2.22.2
Dell ≫ Poweredge Xe7420 Firmware Version < 2.22.2
Dell ≫ Poweredge Xe2420 Firmware Version < 2.22.2
Dell ≫ Dss 8440 Firmware Version < 2.22.2
Dell ≫ Poweredge C4140 Firmware Version < 2.22.2
Dell ≫ Poweredge Mx840c Firmware Version < 2.22.1
Dell ≫ Poweredge Mx740c Firmware Version < 2.22.1
Dell ≫ Poweredge M640 (for Pe Vrtx) Firmware Version < 2.22.2
Dell ≫ Poweredge M640 Firmware Version < 2.22.2
Dell ≫ Poweredge Fc640 Firmware Version < 2.22.2
Dell ≫ Poweredge C6420 Firmware Version < 2.22.2
Dell ≫ Poweredge T640 Firmware Version < 2.22.1
Dell ≫ Poweredge R940xa Firmware Version < 2.22.1
Dell ≫ Poweredge R840 Firmware Version < 2.22.1
Dell ≫ Poweredge R740xd2 Firmware Version < 2.22.1
Dell ≫ Poweredge Xr2 Firmware Version < 2.22.1
Dell ≫ Poweredge T440 Firmware Version < 2.22.1
Dell ≫ Poweredge R440 Firmware Version < 2.22.1
Dell ≫ Poweredge R540 Firmware Version < 2.22.1
Dell ≫ Poweredge R940 Firmware Version < 2.22.2
Dell ≫ Poweredge R640 Firmware Version < 2.22.2
Dell ≫ Poweredge R740xd Firmware Version < 2.22.2
Dell ≫ Poweredge R740 Firmware Version < 2.22.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.275 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2 | 4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
security_alert@emc.com | 3.8 | 2 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
|
CWE-788 Access of Memory Location After End of Buffer
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.