CVE-2024-38303
6.0
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Exploitability: 1.5 / Impact: 4.0
Source: NVD
Description
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Affected (31)
Products: Dell: Emc Xc Core Xcxr2 Firmware, Emc Xc Core Xc940 System Firmware, Emc Xc Core Xc740xd2 Firmware, Emc Xc Core Xc740xd System Firmware, Emc Xc Core Xc640 System Firmware, Emc Xc Core 6420 System Firmware, Emc Storage Nx3340 Firmware, Emc Storage Nx3240 Firmware, Poweredge Xe7440 Firmware, Poweredge Xe7420 Firmware, Poweredge Xe2420 Firmware, Dss 8440 Firmware, Poweredge C4140 Firmware, Poweredge Mx840c Firmware, Poweredge Mx740c Firmware, Poweredge M640 (for Pe Vrtx) Firmware, Poweredge M640 Firmware, Poweredge Fc640 Firmware, Poweredge C6420 Firmware, Poweredge T640 Firmware, Poweredge R940xa Firmware, Poweredge R840 Firmware, Poweredge R740xd2 Firmware, Poweredge Xr2 Firmware, Poweredge T440 Firmware, Poweredge R440 Firmware, Poweredge R540 Firmware, Poweredge R940 Firmware, Poweredge R640 Firmware, Poweredge R740xd Firmware, Poweredge R740 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core Xcxr2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core Xc940 System | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core Xc740xd2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core Xc740xd System | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core Xc640 System | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Xc Core 6420 System | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Storage Nx3340 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Storage Nx3240 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Xe7440 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Xe7420 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Xe2420 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Dss 8440 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge C4140 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Mx840c | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Mx740c | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge M640 (for Pe Vrtx) | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge M640 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Fc640 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge C6420 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge T640 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R940xa | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R840 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R740xd2 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge Xr2 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge T440 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R440 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R540 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R940 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R640 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R740xd | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.22.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Poweredge R740 | All versions |
References (1)
Source: security_alert@emc.com
Vendor Advisory
Timeline
No history available yet.