CVE Feed

    Dashboard / CVE / CVE-2024-38303

    CVE-2024-38303

    Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published:Aug 29, 2024
    Last Modified:Dec 20, 2024
    EPS:Aug 29, 2024
    EPSS Score:0.00026
    CVSS Score:5.3

    Affected Products

    Vendor
    Dell
    Product
    Dss 8440
    Vendor
    Dell
    Product
    Dss 8440 Firmware
    Vendor
    Dell
    Product
    Emc Storage Nx3240
    Vendor
    Dell
    Product
    Emc Storage Nx3240 Firmware
    Vendor
    Dell
    Product
    Emc Storage Nx3340
    Vendor
    Dell
    Product
    Emc Storage Nx3340 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core 6420 System
    Vendor
    Dell
    Product
    Emc Xc Core 6420 System Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc640 System
    Vendor
    Dell
    Product
    Emc Xc Core Xc640 System Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd2
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd2 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd System
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd System Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc940 System
    Vendor
    Dell
    Product
    Emc Xc Core Xc940 System Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xcxr2
    Vendor
    Dell
    Product
    Emc Xc Core Xcxr2 Firmware
    Vendor
    Dell
    Product
    Poweredge C4140
    Vendor
    Dell
    Product
    Poweredge C4140 Firmware
    Vendor
    Dell
    Product
    Poweredge C6420
    Vendor
    Dell
    Product
    Poweredge C6420 Firmware
    Vendor
    Dell
    Product
    Poweredge Fc640
    Vendor
    Dell
    Product
    Poweredge Fc640 Firmware
    Vendor
    Dell
    Product
    Poweredge M640
    Vendor
    Dell
    Product
    Poweredge M640 \(for Pe Vrtx\)
    Vendor
    Dell
    Product
    Poweredge M640 \(for Pe Vrtx\) Firmware
    Vendor
    Dell
    Product
    Poweredge M640 Firmware
    Vendor
    Dell
    Product
    Poweredge Mx740c
    Vendor
    Dell
    Product
    Poweredge Mx740c Firmware
    Vendor
    Dell
    Product
    Poweredge Mx840c
    Vendor
    Dell
    Product
    Poweredge Mx840c Firmware
    Vendor
    Dell
    Product
    Poweredge R440
    Vendor
    Dell
    Product
    Poweredge R440 Firmware
    Vendor
    Dell
    Product
    Poweredge R540
    Vendor
    Dell
    Product
    Poweredge R540 Firmware
    Vendor
    Dell
    Product
    Poweredge R640
    Vendor
    Dell
    Product
    Poweredge R640 Firmware
    Vendor
    Dell
    Product
    Poweredge R740
    Vendor
    Dell
    Product
    Poweredge R740 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd
    Vendor
    Dell
    Product
    Poweredge R740xd2
    Vendor
    Dell
    Product
    Poweredge R740xd2 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd Firmware
    Vendor
    Dell
    Product
    Poweredge R840
    Vendor
    Dell
    Product
    Poweredge R840 Firmware
    Vendor
    Dell
    Product
    Poweredge R940
    Vendor
    Dell
    Product
    Poweredge R940 Firmware
    Vendor
    Dell
    Product
    Poweredge R940xa
    Vendor
    Dell
    Product
    Poweredge R940xa Firmware
    Vendor
    Dell
    Product
    Poweredge T440
    Vendor
    Dell
    Product
    Poweredge T440 Firmware
    Vendor
    Dell
    Product
    Poweredge T640
    Vendor
    Dell
    Product
    Poweredge T640 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe2420
    Vendor
    Dell
    Product
    Poweredge Xe2420 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe7420
    Vendor
    Dell
    Product
    Poweredge Xe7420 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe7440
    Vendor
    Dell
    Product
    Poweredge Xe7440 Firmware
    Vendor
    Dell
    Product
    Poweredge Xr2
    Vendor
    Dell
    Product
    Poweredge Xr2 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High