Attacker Value
Unknown
0
CVE-2024-32855
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2024-32855
(Last updated February 05, 2025) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
4.4 Medium
Impact Score:
3.6
Exploitability Score:
0.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
High
Availability (A):
None
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
CPG BIOS 1.30.0
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- inspiron 3480 firmware,
- inspiron 3580 firmware,
- latitude 3120 firmware,
- latitude 3190 2-in-1 firmware,
- latitude 3190 firmware,
- latitude 3300 firmware,
- latitude 3310 2-in-1 firmware,
- latitude 3310 firmware,
- latitude 3390 2-in-1 firmware,
- latitude 5288 firmware,
- latitude 5290 2-in-1 firmware,
- latitude 5290 firmware,
- latitude 5300 2-in-1 firmware,
- latitude 5300 firmware,
- latitude 5310 2-in-1 firmware,
- latitude 5310 firmware,
- latitude 5400 firmware,
- latitude 5401 firmware,
- latitude 5410 firmware,
- latitude 5411 firmware,
- latitude 5420 rugged firmware,
- latitude 5424 rugged firmware,
- latitude 5480 firmware,
- latitude 5488 firmware,
- latitude 5490 firmware,
- latitude 5491 firmware,
- latitude 5500 firmware,
- latitude 5501 firmware,
- latitude 5510 firmware,
- latitude 5511 firmware,
- latitude 5580 firmware,
- latitude 5590 firmware,
- latitude 5591 firmware,
- latitude 7200 2-in-1 firmware,
- latitude 7210 2-in-1 firmware,
- latitude 7212 rugged extreme tablet firmware,
- latitude 7220 rugged extreme firmware,
- latitude 7280 firmware,
- latitude 7290 firmware,
- latitude 7300 firmware,
- latitude 7310 firmware,
- latitude 7380 firmware,
- latitude 7390 2-in-1 firmware,
- latitude 7390 firmware,
- latitude 7400 2-in-1 firmware,
- latitude 7400 firmware,
- latitude 7410 firmware,
- latitude 7424 rugged extreme firmware,
- latitude 7480 firmware,
- latitude 7490 firmware,
- latitude 9410 firmware,
- latitude 9510 2in1 firmware,
- latitude rugged 7220ex firmware,
- precision 3520 firmware,
- precision 3530 firmware,
- precision 3540 firmware,
- precision 3541 firmware,
- precision 3550 firmware,
- precision 3551 firmware,
- precision 5530 2-in-1 firmware,
- precision 5530 firmware,
- precision 5540 firmware,
- precision 7530 firmware,
- precision 7540 firmware,
- precision 7550 firmware,
- precision 7730 firmware,
- precision 7740 firmware,
- precision 7750 firmware,
- vostro 3480 firmware,
- vostro 3580 firmware,
- vostro 3583 firmware,
- wyse 5470 all-in-one firmware,
- wyse 5470 firmware,
- xps 15 7590 firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: