Lucene search

K
cveDellCVE-2024-0160
HistoryJun 12, 2024 - 7:15 a.m.

CVE-2024-0160

2024-06-1207:15:50
CWE-863
dell
web.nvd.nist.gov
37
dell client platform
authorization vulnerability
bios modification

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

22.3%

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
dellxps_17_9700_firmwareRange<1.30.0
AND
dellxps_17_9700Match-
Node
dellxps_15_9500_firmwareRange<1.31.0
AND
dellxps_15_9500Match-
Node
dellvostro_7500_firmwareRange<1.28.0
AND
dellvostro_7500Match-
Node
dellprecision_5750_firmwareRange<1.30.0
AND
dellprecision_5750Match-
Node
dellprecision_5550_firmwareRange<1.31.0
AND
dellprecision_5550Match-
Node
delllatitude_3520_firmwareRange<1.36.0
AND
delllatitude_3520Match-
Node
delllatitude_3510_firmwareRange<1.29.0
AND
delllatitude_3510Match-
Node
delllatitude_3420_firmwareRange<1.36.0
AND
delllatitude_3420Match-
Node
delllatitude_3410_firmwareRange<1.29.0
AND
delllatitude_3410Match-
Node
dellinspiron_7501_firmwareRange<1.28.0
AND
dellinspiron_7501Match-
Node
dellinspiron_7500_firmwareRange<1.28.0
AND
dellinspiron_7500Match-
Node
dellg7_7700_firmwareRange<1.32.0
AND
dellg7_7700Match-
Node
dellg7_7500_firmwareRange<1.32.0
AND
dellg7_7500Match-
Node
dellg5_5500_firmwareRange<1.30.0
AND
dellg5_5500Match-
Node
dellg3_3500_firmwareRange<1.30.0
AND
dellg3_3500Match-
VendorProductVersionCPE
dellxps_17_9700_firmware*cpe:2.3:o:dell:xps_17_9700_firmware:*:*:*:*:*:*:*:*
dellxps_17_9700-cpe:2.3:h:dell:xps_17_9700:-:*:*:*:*:*:*:*
dellxps_15_9500_firmware*cpe:2.3:o:dell:xps_15_9500_firmware:*:*:*:*:*:*:*:*
dellxps_15_9500-cpe:2.3:h:dell:xps_15_9500:-:*:*:*:*:*:*:*
dellvostro_7500_firmware*cpe:2.3:o:dell:vostro_7500_firmware:*:*:*:*:*:*:*:*
dellvostro_7500-cpe:2.3:h:dell:vostro_7500:-:*:*:*:*:*:*:*
dellprecision_5750_firmware*cpe:2.3:o:dell:precision_5750_firmware:*:*:*:*:*:*:*:*
dellprecision_5750-cpe:2.3:h:dell:precision_5750:-:*:*:*:*:*:*:*
dellprecision_5550_firmware*cpe:2.3:o:dell:precision_5550_firmware:*:*:*:*:*:*:*:*
dellprecision_5550-cpe:2.3:h:dell:precision_5550:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CPG BIOS",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "1.32.0",
        "status": "affected",
        "version": "N/A",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

22.3%

Related for CVE-2024-0160