CVE-2024-38304

Published Aug 29, 2024

Last updated a year ago

Overview

Description
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Source
security_alert@emc.com
NVD status
Analyzed
Products
emc_xc_core_xcxr2_firmware, emc_xc_core_xc940_system_firmware, emc_xc_core_xc740xd2_firmware, emc_xc_core_xc740xd_system_firmware, emc_xc_core_xc640_system_firmware, emc_xc_core_6420_system_firmware, emc_storage_nx3340_firmware, emc_storage_nx3240_firmware, poweredge_xe7440_firmware, poweredge_xe7420_firmware, poweredge_xe2420_firmware, dss_8440_firmware, poweredge_c4140_firmware, poweredge_mx840c_firmware, poweredge_mx740c_firmware, poweredge_m640_\(for_pe_vrtx\)_firmware, poweredge_m640_firmware, poweredge_fc640_firmware, poweredge_c6420_firmware, poweredge_t640_firmware, poweredge_r940xa_firmware, poweredge_r840_firmware, poweredge_r740xd2_firmware, poweredge_xr2_firmware, poweredge_t440_firmware, poweredge_r440_firmware, poweredge_r540_firmware, poweredge_r940_firmware, poweredge_r640_firmware, poweredge_r740xd_firmware, poweredge_r740_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
4
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

security_alert@emc.com
CWE-788
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations