CVE-2024-28970
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 0.8 / Impact: 3.6
Source: NVD
Description
Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.
Affected (14)
Products: Dell: Vostro 5502 Firmware, Vostro 5402 Firmware, Precision 3660 Firmware, Inspiron 5509 Firmware, Inspiron 5502 Firmware, Inspiron 5409 Firmware, Inspiron 5402 Firmware, Inspiron 27 7720 All In One Firmware, Inspiron 24 5420 All In One Firmware, Inspiron 16 Plus 7640 Firmware, Inspiron 16 7640 2 In 1 Firmware, Inspiron 14 Plus 7440 Firmware, G7 7700 Firmware, G7 7500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 5502 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 5402 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Precision 3660 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 5509 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 5502 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 5409 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.30.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 5402 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 27 7720 All In One | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 24 5420 All In One | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.6.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 16 Plus 7640 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 16 7640 2 In 1 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.6.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 14 Plus 7440 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.32.0 |
| Running on/with | Platform Versions |
|---|---|
Dell G7 7700 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.32.0 |
| Running on/with | Platform Versions |
|---|---|
Dell G7 7500 | All versions |
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.