6.7

CVE-2024-38483

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Latitude 5290 2-in-1 Firmware Version < 1.35.0
   Dell ≫ Latitude 5290 2-in-1 Version -
Dell ≫ Precision 3420 Tower Firmware Version < 2.32.0
   Dell ≫ Precision 3420 Version -
Dell ≫ Precision 3620 Firmware Version < 2.32.0
   Dell ≫ Precision 3620 Tower Version -
Dell ≫ Wyse 7040 Thin Client Firmware Version < 1.26.0
   Dell ≫ Wyse 7040 Thin Client Version -
Dell ≫ Precision 7720 Firmware Version < 1.37.0
   Dell ≫ Precision 7720 Version -
Dell ≫ Precision 7520 Firmware Version 1.37.0
   Dell ≫ Precision 7520 Version -
Dell ≫ Precision 5530 2-in-1 Firmware Version < 1.32.8
   Dell ≫ Precision 5530 2-in-1 Version -
Dell ≫ Precision 5520 Firmware Version < 1.39.0
   Dell ≫ Precision 5520 Version -
Dell ≫ Precision 3520 Firmware Version < 1.37.0
   Dell ≫ Precision 3520 Version -
Dell ≫ Optiplex 7450 All-in-one Firmware Version < 1.34.0
   Dell ≫ Optiplex 7450 All-in-one Version -
Dell ≫ Optiplex 5050 Firmware Version < 1.31.0
   Dell ≫ Optiplex 5050 Version -
Dell ≫ Optiplex 3050 All-in-one Firmware Version < 1.34.0
   Dell ≫ Optiplex 3050 All-in-one Version -
Dell ≫ Optiplex 3050 Firmware Version < 1.31.0
   Dell ≫ Optiplex 3050 Version -
Dell ≫ Latitude 7490 Firmware Version < 1.39.0
   Dell ≫ Latitude 7490 Version -
Dell ≫ Latitude 7480 Firmware Version < 1.38.0
   Dell ≫ Latitude 7480 Version -
Dell ≫ Latitude 7414 Rugged Firmware Version < 1.47.0
   Dell ≫ Latitude 7414 Rugged Version -
Dell ≫ Latitude 7390 2-in-1 Firmware Version < 1.36.0
   Dell ≫ Latitude 7390 2-in-1 Version -
Dell ≫ Latitude 7390 Firmware Version < 1.39.0
   Dell ≫ Latitude 7390 Version -
Dell ≫ Latitude 7380 Firmware Version < 1.38.0
   Dell ≫ Latitude 7380 Version -
Dell ≫ Latitude 7290 Firmware Version < 1.39.0
   Dell ≫ Latitude 7290 Version -
Dell ≫ Latitude 7285 2-in-1 Firmware Version < 1.27.0
   Dell ≫ Latitude 7285 2-in-1 Version -
Dell ≫ Latitude 7280 Firmware Version < 1.38.0
   Dell ≫ Latitude 7280 Version -
Dell ≫ Latitude 5590 Firmware Version < 1.36.0
   Dell ≫ Latitude 5590 Version -
Dell ≫ Latitude 5580 Firmware Version < 1.37.0
   Dell ≫ Latitude 5580 Version -
Dell ≫ Latitude 5490 Firmware Version < 1.36.0
   Dell ≫ Latitude 5490 Version -
Dell ≫ Latitude 5488 Firmware Version < 1.37.0
   Dell ≫ Latitude 5488 Version -
Dell ≫ Latitude 5480 Firmware Version < 1.37.0
   Dell ≫ Latitude 5480 Version -
Dell ≫ Latitude 5424 Rugged Firmware Version < 1.34.0
   Dell ≫ Latitude 5424 Rugged Version -
Dell ≫ Latitude 5420 Rugged Firmware Version < 1.34.0
   Dell ≫ Latitude 5420 Rugged Version -
Dell ≫ Latitude 5414 Rugged Firmware Version < 1.47.0
   Dell ≫ Latitude 5414 Rugged Version -
Dell ≫ Latitude 5400 Firmware Version < 1.32.0
   Dell ≫ Latitude 5400 Version -
Dell ≫ Latitude 5290 Firmware Version < 1.36.0
   Dell ≫ Latitude 5290 Version -
Dell ≫ Latitude 5288 Firmware Version < 1.37.0
   Dell ≫ Latitude 5288 Version -
Dell ≫ Latitude 5280 Firmware Version < 1.37.0
   Dell ≫ Latitude 5280 Version -
Dell ≫ Latitude 3390 2-in-1 Firmware Version < 1.32.0
   Dell ≫ Latitude 3390 2-in-1 Version -
Dell ≫ Latitude 3300 Firmware Version < 1.29.0
   Dell ≫ Latitude 3300 Version -
Dell ≫ Latitude 13 3380 Firmware Version < 1.28.0
   Dell ≫ Latitude 13 3380 Version -
Dell ≫ Embedded Box Pc 5000 Firmware Version < 1.26.0
   Dell ≫ Embedded Box Pc 5000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.046
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EMC 5.8 0.3 5.5
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.dell.com/support/kbdoc/en-us/000225776/dsa-2024-260
Vendor Advisory