Attacker Value
Unknown
0
CVE-2024-22429
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2024-22429
(Last updated January 31, 2025) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
CPG BIOS 2.36.0
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- edge gateway 3000 firmware,
- edge gateway 5000 firmware,
- embedded box pc 3000 firmware,
- embedded box pc 5000 firmware,
- latitude 12 rugged extreme 7214 firmware,
- latitude 13 3380 firmware,
- latitude 3180 firmware,
- latitude 3189 firmware,
- latitude 3190 2-in-1 firmware,
- latitude 3190 firmware,
- latitude 3300 firmware,
- latitude 3390 2-in-1 firmware,
- latitude 5280 firmware,
- latitude 5288 firmware,
- latitude 5290 2-in-1 firmware,
- latitude 5290 firmware,
- latitude 5400 firmware,
- latitude 5414 rugged firmware,
- latitude 5420 rugged firmware,
- latitude 5424 rugged firmware,
- latitude 5480 firmware,
- latitude 5488 firmware,
- latitude 5490 firmware,
- latitude 5580 firmware,
- latitude 5590 firmware,
- latitude 7212 rugged extreme tablet firmware,
- latitude 7280 firmware,
- latitude 7285 2-in-1 firmware,
- latitude 7290 firmware,
- latitude 7380 firmware,
- latitude 7390 2-in-1 firmware,
- latitude 7390 firmware,
- latitude 7414 rugged firmware,
- latitude 7424 rugged extreme firmware,
- latitude 7480 firmware,
- latitude 7490 firmware,
- optiplex 3050 all-in-one firmware,
- optiplex 3050 firmware,
- optiplex 5050 firmware,
- optiplex 7450 all-in-one firmware,
- precision 3420 tower firmware,
- precision 3520 firmware,
- precision 3620 tower firmware,
- precision 5520 firmware,
- precision 5530 2-in-1 firmware,
- precision 5820 tower firmware,
- precision 7520 firmware,
- precision 7720 firmware,
- wyse 5070 firmware,
- wyse 7040 thin client firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: