CVE-2024-38303

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
dellCNA
5.3 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
dellemc_xc_core_xcxr2_firmware
𝑥
< 2.22.1
dellemc_xc_core_xc940_system_firmware
𝑥
< 2.22.2
dellemc_xc_core_xc740xd2_firmware
𝑥
< 2.22.1
dellemc_xc_core_xc740xd_system_firmware
𝑥
< 2.22.2
dellemc_xc_core_xc640_system_firmware
𝑥
< 2.22.2
dellemc_xc_core_6420_system_firmware
𝑥
< 2.22.2
dellemc_storage_nx3340_firmware
𝑥
< 2.22.2
dellemc_storage_nx3240_firmware
𝑥
< 2.22.2
dellpoweredge_xe7440_firmware
𝑥
< 2.22.2
dellpoweredge_xe7420_firmware
𝑥
< 2.22.2
dellpoweredge_xe2420_firmware
𝑥
< 2.22.2
delldss_8440_firmware
𝑥
< 2.22.2
dellpoweredge_c4140_firmware
𝑥
< 2.22.2
dellpoweredge_mx840c_firmware
𝑥
< 2.22.1
dellpoweredge_mx740c_firmware
𝑥
< 2.22.1
dellpoweredge_m640_\(for_pe_vrtx\)_firmware
𝑥
< 2.22.2
dellpoweredge_m640_firmware
𝑥
< 2.22.2
dellpoweredge_fc640_firmware
𝑥
< 2.22.2
dellpoweredge_c6420_firmware
𝑥
< 2.22.2
dellpoweredge_t640_firmware
𝑥
< 2.22.1
dellpoweredge_r940xa_firmware
𝑥
< 2.22.1
dellpoweredge_r840_firmware
𝑥
< 2.22.1
dellpoweredge_r740xd2_firmware
𝑥
< 2.22.1
dellpoweredge_xr2_firmware
𝑥
< 2.22.1
dellpoweredge_t440_firmware
𝑥
< 2.22.1
dellpoweredge_r440_firmware
𝑥
< 2.22.1
dellpoweredge_r540_firmware
𝑥
< 2.22.1
dellpoweredge_r940_firmware
𝑥
< 2.22.2
dellpoweredge_r640_firmware
𝑥
< 2.22.2
dellpoweredge_r740xd_firmware
𝑥
< 2.22.2
dellpoweredge_r740_firmware
𝑥
< 2.22.2
𝑥
= Vulnerable software versions