CVE-2024-28970

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:vostro_5502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:vostro_5502:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:vostro_5402_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:vostro_5402:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:precision_3660_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_3660:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:inspiron_5509_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_5509:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:inspiron_5502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_5502:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:inspiron_5409_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_5409:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:inspiron_5402_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_5402:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:inspiron_27_7720_all-in-one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_27_7720_all-in-one:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dell:inspiron_24_5420_all-in-one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_24_5420_all-in-one:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dell:inspiron_16_plus_7640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_16_plus_7640:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dell:inspiron_16_7640_2-in-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_16_7640_2-in-1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dell:inspiron_14_plus_7440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:inspiron_14_plus_7440:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dell:g7_7700_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:g7_7700:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dell:g7_7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:g7_7500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-12 07:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-28970

Mitre link : CVE-2024-28970

CVE.ORG link : CVE-2024-28970


JSON object : View

Products Affected

dell

  • precision_3660_firmware
  • inspiron_5409
  • inspiron_5509
  • inspiron_24_5420_all-in-one_firmware
  • inspiron_16_plus_7640
  • inspiron_5409_firmware
  • g7_7700
  • inspiron_27_7720_all-in-one
  • inspiron_16_plus_7640_firmware
  • inspiron_27_7720_all-in-one_firmware
  • inspiron_5402_firmware
  • g7_7500_firmware
  • vostro_5402_firmware
  • inspiron_5502
  • inspiron_5502_firmware
  • vostro_5502_firmware
  • inspiron_5402
  • inspiron_24_5420_all-in-one
  • vostro_5502
  • inspiron_14_plus_7440
  • precision_3660
  • inspiron_14_plus_7440_firmware
  • inspiron_5509_firmware
  • g7_7700_firmware
  • vostro_5402
  • g7_7500
  • inspiron_16_7640_2-in-1_firmware
  • inspiron_16_7640_2-in-1
CWE
CWE-787

Out-of-bounds Write