CVE-2024-38303: Input Validation
Published Aug 29, 2024
·Updated
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
62 affected components
All of the following
Dell Emc Xc Core Xcxr2 Firmware<2.22.1
Dell Emc Xc Core Xcxr2
All of the following
Dell Emc Xc Core Xc940 System Firmware<2.22.2
Dell Emc Xc Core Xc940 System
All of the following
Dell Emc Xc Core Xc740xd2 Firmware<2.22.1
Dell Emc Xc Core Xc740xd2
All of the following
Dell Emc Xc Core Xc740xd System Firmware<2.22.2
Dell Emc Xc Core Xc740xd System
All of the following
Dell Emc Xc Core Xc640 System Firmware<2.22.2
Dell Emc Xc Core Xc640 System
All of the following
Dell Emc Xc Core 6420 System Firmware<2.22.2
Dell Emc Xc Core 6420 System
All of the following
Dell Emc Storage Nx3340 Firmware<2.22.2
Dell Emc Storage Nx3340
All of the following
Dell Emc Storage Nx3240 Firmware<2.22.2
Dell Emc Storage Nx3240
All of the following
Dell Poweredge Xe7440 Firmware<2.22.2
Dell Poweredge Xe7440
All of the following
Dell Poweredge Xe7420 Firmware<2.22.2
Dell Poweredge Xe7420
All of the following
Dell Poweredge Xe2420 Firmware<2.22.2
Dell Poweredge Xe2420
All of the following
Dell Dss 8440 Firmware<2.22.2
Dell Dss 8440
All of the following
Dell Poweredge C4140 Firmware<2.22.2
Dell Poweredge C4140
All of the following
Dell Poweredge Mx840c Firmware<2.22.1
Dell Poweredge Mx840c
All of the following
Dell Poweredge Mx740c Firmware<2.22.1
Dell Poweredge Mx740c
All of the following
Dell Poweredge M640 \(for Pe Vrtx\) Firmware<2.22.2
Dell Poweredge M640 \(for Pe Vrtx\)
All of the following
Dell Poweredge M640 Firmware<2.22.2
Dell Poweredge M640
All of the following
Dell Poweredge Fc640 Firmware<2.22.2
Dell Poweredge Fc640
All of the following
Dell Poweredge C6420 Firmware<2.22.2
Dell Poweredge C6420
All of the following
Dell Poweredge T640 Firmware<2.22.1
Dell Poweredge T640
All of the following
Dell Poweredge R940xa Firmware<2.22.1
Dell Poweredge R940xa
All of the following
Dell Poweredge R840 Firmware<2.22.1
Dell Poweredge R840
All of the following
Dell Poweredge R740xd2 Firmware<2.22.1
Dell Poweredge R740xd2
All of the following
Dell Poweredge Xr2 Firmware<2.22.1
Dell Poweredge Xr2
All of the following
Dell Poweredge T440 Firmware<2.22.1
Dell Poweredge T440
All of the following
Dell Poweredge R440 Firmware<2.22.1
Dell Poweredge R440
All of the following
Dell Poweredge R540 Firmware<2.22.1
Dell Poweredge R540
All of the following
Dell Poweredge R940 Firmware<2.22.2
Dell Poweredge R940
All of the following
Dell Poweredge R640 Firmware<2.22.2
Dell PowerEdge R640
All of the following
Dell Poweredge R740xd Firmware<2.22.2
Dell Poweredge R740xd
All of the following
Dell Poweredge R740 Firmware<2.22.2
Dell Poweredge R740
Event History
Aug 29, 2024
CVE Published
via MITRE·04:34 AM
Data Sourced
via MITRE·04:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38303?
The severity of CVE-2024-38303 is high due to its potential for information disclosure by a privileged attacker with local access.
2
How do I fix CVE-2024-38303?
To fix CVE-2024-38303, update the affected Dell PowerEdge systems to BIOS version 2.22.x or later.
3
Which Dell systems are affected by CVE-2024-38303?
CVE-2024-38303 affects various Dell PowerEdge models with BIOS versions prior to 2.22.x.
4
What type of vulnerability is CVE-2024-38303?
CVE-2024-38303 is classified as an Improper Input Validation vulnerability.
5
Can CVE-2024-38303 be exploited remotely?
No, CVE-2024-38303 requires local access for exploitation by a high privileged attacker.