CVE-2024-0160

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
dellCNA
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
dellxps_17_9700_firmware
𝑥
< 1.30.0
dellxps_15_9500_firmware
𝑥
< 1.31.0
dellvostro_7500_firmware
𝑥
< 1.28.0
dellprecision_5750_firmware
𝑥
< 1.30.0
dellprecision_5550_firmware
𝑥
< 1.31.0
delllatitude_3520_firmware
𝑥
< 1.36.0
delllatitude_3510_firmware
𝑥
< 1.29.0
delllatitude_3420_firmware
𝑥
< 1.36.0
delllatitude_3410_firmware
𝑥
< 1.29.0
dellinspiron_7501_firmware
𝑥
< 1.28.0
dellinspiron_7500_firmware
𝑥
< 1.28.0
dellg7_7700_firmware
𝑥
< 1.32.0
dellg7_7500_firmware
𝑥
< 1.32.0
dellg5_5500_firmware
𝑥
< 1.30.0
dellg3_3500_firmware
𝑥
< 1.30.0
𝑥
= Vulnerable software versions