CVE-2024-28970
MEDIUMDell Client BIOS - Authenticated Denial of Service via Out-of-bounds Write
Title source: llmDescription
Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.dell.com/support/kbdoc/en-us/000225476/dsa-2024-168
Scores
CVSS v3
4.7
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-787
Status
published
Products (14)
dell/g7_7500_firmware
< 1.32.0
dell/g7_7700_firmware
< 1.32.0
dell/inspiron_14_plus_7440_firmware
< 1.6.0
dell/inspiron_16_7640_2-in-1_firmware
< 1.4.0
dell/inspiron_16_plus_7640_firmware
< 1.6.0
dell/inspiron_24_5420_all-in-one_firmware
< 1.11.0
dell/inspiron_27_7720_all-in-one_firmware
< 1.11.0
dell/inspiron_5402_firmware
< 1.30.0
dell/inspiron_5409_firmware
< 1.30.0
dell/inspiron_5502_firmware
< 1.30.0
... and 4 more
Published
Jun 12, 2024
Tracked Since
Feb 18, 2026