First published: Thu Aug 29 2024(Updated: )
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Dell EMC XC Core XCX-R2 | <2.22.1 | |
Dell EMC XC Core XCX-R2 | ||
All of | ||
Dell EMC XC Core XC940 System | <2.22.2 | |
Dell EMC XC Core XC940 System | ||
All of | ||
Dell EMC XC Core XC740XD2 Firmware | <2.22.1 | |
Dell EMC XC Core XC740XD2 Firmware | ||
All of | ||
Dell EMC XC Core XC740XD System | <2.22.2 | |
Dell EMC XC Core XC740XD System | ||
All of | ||
Dell EMC XC Core XC640 System | <2.22.2 | |
Dell EMC XC Core XC640 System | ||
All of | ||
Dell EMC XC Core 6420 System Firmware | <2.22.2 | |
Dell EMC XC Core 6420 System | ||
All of | ||
Dell NX3340 Firmware | <2.22.2 | |
Dell emc storage nx3340 | ||
All of | ||
Dell NX3240 Firmware | <2.22.2 | |
Dell emc storage nx3240 | ||
All of | ||
Dell PowerEdge xe7440 | <2.22.2 | |
Dell PowerEdge xe7440 firmware | ||
All of | ||
Dell XE7420 Firmware | <2.22.2 | |
Dell PowerEdge xe7420 firmware | ||
All of | ||
Dell PowerEdge XE2420 Firmware | <2.22.2 | |
Dell PowerEdge xe2420 firmware | ||
All of | ||
Dell DSS 8440 Firmware | <2.22.2 | |
Dell DSS 8440 Firmware | ||
All of | ||
Dell PowerEdge C4140 Firmware | <2.22.2 | |
Dell PowerEdge C4140 | ||
All of | ||
Dell PowerEdge MX840c Firmware | <2.22.1 | |
Dell PowerEdge mx840c firmware | ||
All of | ||
Dell PowerEdge MX740c Firmware | <2.22.1 | |
Dell MX740c | ||
All of | ||
Dell PowerEdge m640 (for pe vrtx) firmware | <2.22.2 | |
Dell PowerEdge m640 | ||
All of | ||
Dell PowerEdge m640 | <2.22.2 | |
Dell PowerEdge m640 Firmware | ||
All of | ||
Dell PowerEdge FC640 | <2.22.2 | |
Dell PowerEdge FC640 | ||
All of | ||
Dell PowerEdge C6420 Firmware | <2.22.2 | |
Dell PowerEdge c6420 firmware | ||
All of | ||
Dell PowerEdge T640 Firmware | <2.22.1 | |
Dell PowerEdge T640 | ||
All of | ||
Dell PowerEdge R940xa | <2.22.1 | |
Dell PowerEdge R940xa | ||
All of | ||
Dell PowerEdge R840 Firmware | <2.22.1 | |
Dell PowerEdge R840 Firmware | ||
All of | ||
Dell PowerEdge R740xd2 Firmware | <2.22.1 | |
Dell PowerEdge R740xd2 Firmware | ||
All of | ||
Dell PowerEdge XR2 Firmware | <2.22.1 | |
Dell PowerEdge XR2 Firmware | ||
All of | ||
Dell PowerEdge T440 | <2.22.1 | |
Dell PowerEdge T440 Firmware | ||
All of | ||
Dell PowerEdge R440 Firmware | <2.22.1 | |
Dell PowerEdge R440 Firmware | ||
All of | ||
Dell PowerEdge R540 Firmware | <2.22.1 | |
Dell PowerEdge R540 Firmware | ||
All of | ||
Dell PowerEdge R940 Firmware | <2.22.2 | |
Dell PowerEdge R940xa Firmware | ||
All of | ||
Dell PowerEdge R640 Firmware | <2.22.2 | |
Dell PowerEdge R640 Firmware | ||
All of | ||
Dell PowerEdge R740xd Firmware | <2.22.2 | |
Dell PowerEdge R740xd2 | ||
All of | ||
Dell PowerEdge R740 Firmware | <2.22.2 | |
Dell PowerEdge R740 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-38304 is categorized as low since it involves information disclosure through access of memory location after the end of buffer.
To fix CVE-2024-38304, update the affected Dell PowerEdge Platform BIOS to version 2.22.x or later.
CVE-2024-38304 affects various Dell PowerEdge platforms specifically with Intel BIOS versions prior to 2.22.x.
CVE-2024-38304 is classified as an Access of Memory Location After End of Buffer vulnerability.
No, CVE-2024-38304 requires local access for exploitation, making it a low privilege attack.