8.2

CVE-2024-39584

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability.  A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
DellXps 8960 Firmware Version < 2.12.0
   DellXps 8960 Version-
DellXps 8950 Firmware Version < 1.21.0
   DellXps 8950 Version-
DellInspiron 3502 Firmware Version < 1.18.0
   DellInspiron 3502 Version-
DellInspiron 15 3521 Firmware Version < 1.16.0
   DellInspiron 15 3521 Version-
DellInspiron 15 3510 Firmware Version < 1.21.0
   DellInspiron 15 3510 Version-
DellAurora R16 Firmware Version < 2.13.0
   DellAurora R16 Version-
DellAlienware X17 R2 Firmware Version < 1.22.0
   DellAlienware X17 R2 Version-
DellAlienware X17 R1 Firmware Version < 1.24.0
   DellAlienware X17 R1 Version-
DellAlienware X15 R2 Firmware Version < 1.22.0
   DellAlienware X15 R2 Version-
DellAlienware X15 R1 Firmware Version < 1.24.0
   DellAlienware X15 R1 Version-
DellAlienware X14 Firmware Version < 1.21.0
   DellAlienware X14 Version-
DellAlienware M17 R4 Firmware Version < 1.24.0
   DellAlienware M17 R4 Version-
DellAlienware M17 R3 Firmware Version < 1.29.0
   DellAlienware M17 R3 Version-
DellAlienware M15 R4 Firmware Version < 1.24.0
   DellAlienware M15 R4 Version-
DellAlienware M15 R3 Firmware Version < 1.29.0
   DellAlienware M15 R3 Version-
DellAlienware Aurora R15 Amd Firmware Version < 1.15.0
   DellAlienware Aurora R15 Amd Version-
DellAlienware Aurora R15 Firmware Version < 1.17.0
   DellAlienware Aurora R15 Version-
DellAlienware Aurora R13 Firmware Version < 1.21.0
   DellAlienware Aurora R13 Version-
DellAlienware Area 51m R2 Firmware Version < 1.29.0
   DellAlienware Area 51m R2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.01% 0.004
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
security_alert@emc.com 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-1392 Use of Default Credentials

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.