6.7
CVE-2024-38483
- EPSS 0.03%
- Published 14.08.2024 10:15:06
- Last modified 18.09.2024 19:19:24
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Latitude 5290 2-in-1 Firmware Version < 1.35.0
Dell ≫ Precision 3420 Tower Firmware Version < 2.32.0
Dell ≫ Precision 3620 Firmware Version < 2.32.0
Dell ≫ Wyse 7040 Thin Client Firmware Version < 1.26.0
Dell ≫ Precision 7720 Firmware Version < 1.37.0
Dell ≫ Precision 7520 Firmware Version1.37.0
Dell ≫ Precision 5530 2-in-1 Firmware Version < 1.32.8
Dell ≫ Precision 5520 Firmware Version < 1.39.0
Dell ≫ Precision 3520 Firmware Version < 1.37.0
Dell ≫ Optiplex 7450 All-in-one Firmware Version < 1.34.0
Dell ≫ Optiplex 5050 Firmware Version < 1.31.0
Dell ≫ Optiplex 3050 All-in-one Firmware Version < 1.34.0
Dell ≫ Optiplex 3050 Firmware Version < 1.31.0
Dell ≫ Latitude 7490 Firmware Version < 1.39.0
Dell ≫ Latitude 7480 Firmware Version < 1.38.0
Dell ≫ Latitude 7424 Rugged Extreme Firmware Version < 1.34.0
Dell ≫ Latitude 7414 Rugged Firmware Version < 1.47.0
Dell ≫ Latitude 7390 2-in-1 Firmware Version < 1.36.0
Dell ≫ Latitude 7390 Firmware Version < 1.39.0
Dell ≫ Latitude 7380 Firmware Version < 1.38.0
Dell ≫ Latitude 7290 Firmware Version < 1.39.0
Dell ≫ Latitude 7285 2-in-1 Firmware Version < 1.27.0
Dell ≫ Latitude 7280 Firmware Version < 1.38.0
Dell ≫ Latitude 7212 Rugged Extreme Tablet Firmware Version < 1.51.0
Dell ≫ Latitude 5590 Firmware Version < 1.36.0
Dell ≫ Latitude 5580 Firmware Version < 1.37.0
Dell ≫ Latitude 5490 Firmware Version < 1.36.0
Dell ≫ Latitude 5488 Firmware Version < 1.37.0
Dell ≫ Latitude 5480 Firmware Version < 1.37.0
Dell ≫ Latitude 5424 Rugged Firmware Version < 1.34.0
Dell ≫ Latitude 5420 Rugged Firmware Version < 1.34.0
Dell ≫ Latitude 5414 Rugged Firmware Version < 1.47.0
Dell ≫ Latitude 5400 Firmware Version < 1.32.0
Dell ≫ Latitude 5290 Firmware Version < 1.36.0
Dell ≫ Latitude 5288 Firmware Version < 1.37.0
Dell ≫ Latitude 5280 Firmware Version < 1.37.0
Dell ≫ Latitude 3390 2-in-1 Firmware Version < 1.32.0
Dell ≫ Latitude 3300 Firmware Version < 1.29.0
Dell ≫ Latitude 13 3380 Firmware Version < 1.28.0
Dell ≫ Latitude 12 Rugged Extreme 7214 Firmware Version < 1.47.0
Dell ≫ Embedded Box Pc 5000 Firmware Version < 1.26.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.086 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
security_alert@emc.com | 5.8 | 0.3 | 5.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.