6.7

CVE-2024-47238

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Embedded Box Pc 3000 Firmware Version < 1.25.0
   Dell ≫ Embedded Box Pc 3000 Version -
Dell ≫ Edge Gateway 3001 Firmware Version < 1.19.0
   Dell ≫ Edge Gateway 3001 Version -
Dell ≫ Edge Gateway 3002 Firmware Version < 1.19.0
   Dell ≫ Edge Gateway 3002 Version -
Dell ≫ Edge Gateway 3003 Firmware Version < 1.19.0
   Dell ≫ Edge Gateway 3003 Version -
Dell ≫ Edge Gateway 5000 Firmware Version < 1.29.0
   Dell ≫ Edge Gateway 5000 Version -
Dell ≫ Edge Gateway 5100 Firmware Version < 1.29.0
   Dell ≫ Edge Gateway 5100 Version -
Dell ≫ Edge Gateway 3000 Firmware Version < 1.19.0
   Dell ≫ Edge Gateway 3000 Version -
Dell ≫ Edge Gateway 3200 Firmware Version < 1.19.0
   Dell ≫ Edge Gateway 3200 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.13
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EMC 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355
Vendor Advisory