Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Local
0

CVE-2024-32860

Disclosure Date: June 13, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.2 High
Impact Score:
6
Exploitability Score:
1.5
Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Changed
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • dell

Products

  • alienware area 51m r2 firmware,
  • alienware aurora r11 firmware,
  • alienware aurora r12 firmware,
  • alienware aurora r13 firmware,
  • alienware aurora r15 amd firmware,
  • alienware aurora r15 firmware,
  • alienware aurora ryzen edition r14 firmware,
  • alienware m15 r3 firmware,
  • alienware m15 r4 firmware,
  • alienware m17 r3 firmware,
  • alienware m17 r4 firmware,
  • alienware x14 firmware,
  • alienware x15 r1 firmware,
  • alienware x15 r2 firmware,
  • alienware x17 r1 firmware,
  • alienware x17 r2 firmware,
  • aurora r16 firmware,
  • inspiron 15 3510 firmware,
  • inspiron 15 352 firmware,
  • inspiron 3502 firmware,
  • xps 8950 firmware,
  • xps 8960 firmware

Additional Info

Technical Analysis