Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
0

CVE-2024-38483

Disclosure Date: August 14, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • dell

Products

  • embedded box pc 5000 firmware,
  • latitude 12 rugged extreme 7214 firmware,
  • latitude 13 3380 firmware,
  • latitude 3300 firmware,
  • latitude 3390 2-in-1 firmware,
  • latitude 5280 firmware,
  • latitude 5288 firmware,
  • latitude 5290 2-in-1 firmware,
  • latitude 5290 firmware,
  • latitude 5400 firmware,
  • latitude 5414 rugged firmware,
  • latitude 5420 rugged firmware,
  • latitude 5424 rugged firmware,
  • latitude 5480 firmware,
  • latitude 5488 firmware,
  • latitude 5490 firmware,
  • latitude 5580 firmware,
  • latitude 5590 firmware,
  • latitude 7212 rugged extreme tablet firmware,
  • latitude 7280 firmware,
  • latitude 7285 2-in-1 firmware,
  • latitude 7290 firmware,
  • latitude 7380 firmware,
  • latitude 7390 2-in-1 firmware,
  • latitude 7390 firmware,
  • latitude 7414 rugged firmware,
  • latitude 7424 rugged extreme firmware,
  • latitude 7480 firmware,
  • latitude 7490 firmware,
  • optiplex 3050 all-in-one firmware,
  • optiplex 3050 firmware,
  • optiplex 5050 firmware,
  • optiplex 7450 all-in-one firmware,
  • precision 3420 tower firmware,
  • precision 3520 firmware,
  • precision 3620 firmware,
  • precision 5520 firmware,
  • precision 5530 2-in-1 firmware,
  • precision 7520 firmware 1.37.0,
  • precision 7720 firmware,
  • wyse 7040 thin client firmware

Additional Info

Technical Analysis