8.2
CVE-2024-39584
- EPSS 0.01%
- Published 28.08.2024 06:15:05
- Last modified 20.12.2024 14:38:16
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Xps 8960 Firmware Version < 2.12.0
Dell ≫ Xps 8950 Firmware Version < 1.21.0
Dell ≫ Inspiron 3502 Firmware Version < 1.18.0
Dell ≫ Inspiron 15 3521 Firmware Version < 1.16.0
Dell ≫ Inspiron 15 3510 Firmware Version < 1.21.0
Dell ≫ Aurora R16 Firmware Version < 2.13.0
Dell ≫ Alienware X17 R2 Firmware Version < 1.22.0
Dell ≫ Alienware X17 R1 Firmware Version < 1.24.0
Dell ≫ Alienware X15 R2 Firmware Version < 1.22.0
Dell ≫ Alienware X15 R1 Firmware Version < 1.24.0
Dell ≫ Alienware X14 Firmware Version < 1.21.0
Dell ≫ Alienware M17 R4 Firmware Version < 1.24.0
Dell ≫ Alienware M17 R3 Firmware Version < 1.29.0
Dell ≫ Alienware M15 R4 Firmware Version < 1.24.0
Dell ≫ Alienware M15 R3 Firmware Version < 1.29.0
Dell ≫ Alienware Aurora Ryzen Edition R14 Firmware Version < 2.19.1
Dell ≫ Alienware Aurora R15 Amd Firmware Version < 1.15.0
Dell ≫ Alienware Aurora R15 Firmware Version < 1.17.0
Dell ≫ Alienware Aurora R13 Firmware Version < 1.21.0
Dell ≫ Alienware Area 51m R2 Firmware Version < 1.29.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.004 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
security_alert@emc.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-1392 Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.