CVE-2024-28970

MEDIUM

Dell Client BIOS - Authenticated Denial of Service via Out-of-bounds Write

Title source: llm
STIX 2.1

Description

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (14)
dell/g7_7500_firmware < 1.32.0
dell/g7_7700_firmware < 1.32.0
dell/inspiron_14_plus_7440_firmware < 1.6.0
dell/inspiron_16_7640_2-in-1_firmware < 1.4.0
dell/inspiron_16_plus_7640_firmware < 1.6.0
dell/inspiron_24_5420_all-in-one_firmware < 1.11.0
dell/inspiron_27_7720_all-in-one_firmware < 1.11.0
dell/inspiron_5402_firmware < 1.30.0
dell/inspiron_5409_firmware < 1.30.0
dell/inspiron_5502_firmware < 1.30.0
... and 4 more
Published Jun 12, 2024
Tracked Since Feb 18, 2026