8.2

CVE-2024-39584

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability.  A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Xps 8960 Firmware Version < 2.12.0
   Dell ≫ Xps 8960 Version -
Dell ≫ Xps 8950 Firmware Version < 1.21.0
   Dell ≫ Xps 8950 Version -
Dell ≫ Inspiron 3502 Firmware Version < 1.18.0
   Dell ≫ Inspiron 3502 Version -
Dell ≫ Inspiron 15 3521 Firmware Version < 1.16.0
   Dell ≫ Inspiron 15 3521 Version -
Dell ≫ Inspiron 15 3510 Firmware Version < 1.21.0
   Dell ≫ Inspiron 15 3510 Version -
Dell ≫ Aurora R16 Firmware Version < 2.13.0
   Dell ≫ Aurora R16 Version -
Dell ≫ Alienware X17 R2 Firmware Version < 1.22.0
   Dell ≫ Alienware X17 R2 Version -
Dell ≫ Alienware X17 R1 Firmware Version < 1.24.0
   Dell ≫ Alienware X17 R1 Version -
Dell ≫ Alienware X15 R2 Firmware Version < 1.22.0
   Dell ≫ Alienware X15 R2 Version -
Dell ≫ Alienware X15 R1 Firmware Version < 1.24.0
   Dell ≫ Alienware X15 R1 Version -
Dell ≫ Alienware X14 Firmware Version < 1.21.0
   Dell ≫ Alienware X14 Version -
Dell ≫ Alienware M17 R4 Firmware Version < 1.24.0
   Dell ≫ Alienware M17 R4 Version -
Dell ≫ Alienware M17 R3 Firmware Version < 1.29.0
   Dell ≫ Alienware M17 R3 Version -
Dell ≫ Alienware M15 R4 Firmware Version < 1.24.0
   Dell ≫ Alienware M15 R4 Version -
Dell ≫ Alienware M15 R3 Firmware Version < 1.29.0
   Dell ≫ Alienware M15 R3 Version -
Dell ≫ Alienware Aurora R15 Amd Firmware Version < 1.15.0
   Dell ≫ Alienware Aurora R15 Amd Version -
Dell ≫ Alienware Aurora R15 Firmware Version < 1.17.0
   Dell ≫ Alienware Aurora R15 Version -
Dell ≫ Alienware Aurora R13 Firmware Version < 1.21.0
   Dell ≫ Alienware Aurora R13 Version -
Dell ≫ Alienware Area 51m R2 Firmware Version < 1.29.0
   Dell ≫ Alienware Area 51m R2 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EMC 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-1392 Use of Default Credentials

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

https://www.dell.com/support/kbdoc/en-us/000227594/dsa-2024-354
Vendor Advisory