CVE-2024-0160

EUVD-2024-15959
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
dellCNA
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
dellxps_17_9700_firmware
𝑥
< 1.30.0
dellxps_15_9500_firmware
𝑥
< 1.31.0
dellvostro_7500_firmware
𝑥
< 1.28.0
dellprecision_5750_firmware
𝑥
< 1.30.0
dellprecision_5550_firmware
𝑥
< 1.31.0
delllatitude_3520_firmware
𝑥
< 1.36.0
delllatitude_3510_firmware
𝑥
< 1.29.0
delllatitude_3420_firmware
𝑥
< 1.36.0
delllatitude_3410_firmware
𝑥
< 1.29.0
dellinspiron_7501_firmware
𝑥
< 1.28.0
dellinspiron_7500_firmware
𝑥
< 1.28.0
dellg7_7700_firmware
𝑥
< 1.32.0
dellg7_7500_firmware
𝑥
< 1.32.0
dellg5_5500_firmware
𝑥
< 1.30.0
dellg3_3500_firmware
𝑥
< 1.30.0
𝑥
= Vulnerable software versions