Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
04 Feb 2025, 15:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell edge Gateway 3001
Dell edge Gateway 3200 Firmware Dell edge Gateway 3003 Dell edge Gateway 5000 Dell embedded Box Pc 3000 Firmware Dell edge Gateway 5100 Dell edge Gateway 3003 Firmware Dell embedded Box Pc 3000 Dell Dell edge Gateway 3200 Dell edge Gateway 3002 Dell edge Gateway 3001 Firmware Dell edge Gateway 3002 Firmware Dell edge Gateway 3000 Dell edge Gateway 5100 Firmware Dell edge Gateway 5000 Firmware Dell edge Gateway 3000 Firmware |
|
CPE | cpe:2.3:o:dell:edge_gateway_3001_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3003:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3002:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5100:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_3002_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_3000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3000:-:*:*:*:*:*:*:* cpe:2.3:h:dell:embedded_box_pc_3000:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3001:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_3003_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5000:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:embedded_box_pc_3000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_3200_firmware:*:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
References | () https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355 - Vendor Advisory |
12 Dec 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-12 18:15
Updated : 2025-02-04 15:52
NVD link : CVE-2024-47238
Mitre link : CVE-2024-47238
CVE.ORG link : CVE-2024-47238
JSON object : View
Products Affected
dell
- edge_gateway_3001
- edge_gateway_5000
- edge_gateway_5100
- edge_gateway_3002_firmware
- edge_gateway_3000_firmware
- embedded_box_pc_3000_firmware
- edge_gateway_5000_firmware
- edge_gateway_3000
- edge_gateway_3001_firmware
- edge_gateway_3200
- edge_gateway_3200_firmware
- edge_gateway_3002
- edge_gateway_3003
- embedded_box_pc_3000
- edge_gateway_3003_firmware
- edge_gateway_5100_firmware
CWE