CVE-2024-0160: Medium severity dell xps 17 9700 firmware vulnerability
Published Jun 12, 2024
·Updated
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
Affected Software
30 affected components
All of the following
Dell Xps 17 9700 Firmware<1.30.0
Dell Xps 17 9700
All of the following
Dell Xps 15 9500 Firmware<1.31.0
Dell Xps 15 9500
All of the following
Dell Vostro 7500 Firmware<1.28.0
Dell Vostro 7500
All of the following
Dell Precision 5750 Firmware<1.30.0
Dell Precision 5750
All of the following
Dell Precision 5550 Firmware<1.31.0
Dell Precision 5550
All of the following
Dell Latitude 3520 Firmware<1.36.0
Dell Latitude 3520
All of the following
Dell Latitude 3510 Firmware<1.29.0
Dell Latitude 3510
All of the following
Dell Latitude 3420 Firmware<1.36.0
Dell Latitude 3420
All of the following
Dell Latitude 3410 Firmware<1.29.0
Dell Latitude 3410
All of the following
Dell Inspiron 7501 Firmware<1.28.0
Dell Inspiron 7501
All of the following
Dell Inspiron 7500 Firmware<1.28.0
Dell Inspiron 7500
All of the following
Dell G7 7700 Firmware<1.32.0
Dell G7 7700
All of the following
Dell G7 7500 Firmware<1.32.0
Dell G7 7500
All of the following
Dell G5 5500 Firmware<1.30.0
Dell G5 5500
All of the following
Dell G3 3500 Firmware<1.30.0
Dell G3 3500
Event History
Jun 12, 2024
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0160?
CVE-2024-0160 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-0160?
To fix CVE-2024-0160, update the affected firmware to the latest version provided by Dell.
3
Which systems are affected by CVE-2024-0160?
CVE-2024-0160 affects various Dell models including XPS, Vostro, Precision, Latitude, Inspiron, and G series laptops.
4
What type of vulnerability is CVE-2024-0160?
CVE-2024-0160 is an incorrect authorization vulnerability allowing attackers with physical access to bypass BIOS settings.
5
Can CVE-2024-0160 be exploited remotely?
No, CVE-2024-0160 requires physical access to the affected systems to be exploited.