Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
0

CVE-2024-28970

Disclosure Date: June 12, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
4.4 Medium
Impact Score:
3.6
Exploitability Score:
0.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • dell

Products

  • g7 7500 firmware,
  • g7 7700 firmware,
  • inspiron 14 plus 7440 firmware,
  • inspiron 16 7640 2-in-1 firmware,
  • inspiron 16 plus 7640 firmware,
  • inspiron 24 5420 all-in-one firmware,
  • inspiron 27 7720 all-in-one firmware,
  • inspiron 5402 firmware,
  • inspiron 5409 firmware,
  • inspiron 5502 firmware,
  • inspiron 5509 firmware,
  • precision 3660 firmware,
  • vostro 5402 firmware,
  • vostro 5502 firmware

Additional Info

Technical Analysis